boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, July 26, 2026 · all times UTC← 2026-07-25 · archive · 2026-07-27 →

Security Box Score — July 26, 2026

15 CVEs published, led by Microsoft (3).

15 CVEs published July 26, 2026: 1 critical, 7 high, 1 medium, 6 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 0 awaiting enrichment.

Standings

League
MTDYTD2025 same span2025 full
CVEs published795920362——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

850 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux8042284203121163711120.17.8.0016+292 ▲
microsoft663142010598132014286241.77.8.0047+443 ▲
google1191384156633556397760.47.8.0025-588 ▼
red hat1173391613017023200.06.5.0032+9 ▲
apple31072307328876.56.5.0032-12 ▼
canonical72738115000.05.6.0014+1 ▲
suse82141241000.08.5.0039+4 ▲
freebsd01601240000.07.8.0016-2 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+5 ▲
ubiquiti2536142110338.38.8.0049+17 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear62300221000.04.6.0024-11 ▼
fortinet13226610028522.77.3.0039+11 ▲
f58165830416.38.6.0057+2 ▲
vmware8121821718.38.2.0039+5 ▲
checkpoint31236303216.77.7.04550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache1032585510289113310.47.5.0058-1 ▼
mozilla711275142340900.08.1.0031+22 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-17 ▼
github5111280000.06.0.0042+4 ▲
docker070520000.08.2.0016-4 ▼
wordpress22101022100.07.9.8879+2 ▲
kubernetes110001000.02.4.0035+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091379343653322612730.28.1.0036+867 ▲
adobe952392610410541931.37.7.0026-37 ▼
ibm371615254550600.07.5.0036+5 ▲
progress283762470600.07.5.0037+23 ▲
solarwinds15221633010418.29.1.0058+12 ▲
zohocorp362220000.07.8.0146+2 ▲
veeam152300100.08.6.00510
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link8200596300.05.5.0105-1 ▼
siemens7161870000.07.6.00240
abb170430000.07.2.0018-5 ▼
schneider electric060420000.07.8.0042-6 ▼
hikvision550320000.07.2.0038+5 ▲
moxa050320000.07.0.0029-5 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.0034+12 ▲
openclaw441110583914000.07.0.0026-17 ▼
dell4399547443211.07.1.0021+5 ▲
capgo2283242381000.07.1.0037-24 ▼
nvidia41801252160000.07.8.0037+35 ▲
imagemagick3374155612000.05.3.0018-2 ▼
spring073231391000.06.5.0024-72 ▼
itsourcecode1871001952000.02.1.0033-4 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
CVE-2026-0770.634299.19.8
CVE-2026-48282.423998.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-1377310.0.0610
CVE-2026-651610.0.0486
Most disclosures (vendor)
VendorCVEs
oracle1109
linux805
microsoft664
google502
red hat137
apache120
adobe105
ibm80
mozilla72
sourcecodester61
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco11
apple7
google6
fortinet5
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven63
PyPI5
NuGet3
npm3
Packagist1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-25089Fortinet0
CVE-2026-45659Microsoft0
CVE-2026-46817Oracle Corporation0
CVE-2026-48282Adobe0
CVE-2026-48558SimpleHelp0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171712
CVE-2021-27102n/a2021-11-171712
CVE-2021-27101n/a2021-11-171712
CVE-2021-27103n/a2021-11-171712
CVE-2021-21017Adobe2021-11-171712
CVE-2021-28550Adobe2021-11-171712
CVE-2021-42013Apache Software Foundation2021-11-171712
CVE-2021-41773Apache Software Foundation2021-11-171712
CVE-2021-30858Apple2021-11-171712
CVE-2021-30860Apple2021-11-171712

Transactions

EXPLOIT PUBLISHED — CVE-2026-16735 (release-it conventional-changelog). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-65700 (h2oai h2ogpt). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-65707 (likeadmin-likeshop likeshop). Public exploit reference added.

DUE DATE PASSED — CVE-2026-16232 (checkpoint Quantum Security Management). CISA remediation deadline was July 25, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-50522 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 25, 2026; still in catalog.

ENRICHED — CVE-2020-19909. Received CVSS 3.3 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

15 CVEs published. 15 box scores, 0 table rows — nothing truncated.

koxudaxi datamodel-code-generator — datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   A   H   H   H    7.5   .0075   52.2     —
AFFECTED
  Product                   Versions     Fixed
  datamodel-code-generator  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Jul 26  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred
Linux Linux — net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0054   42.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    172ba7d46c202e679f3ccb10264c67416aaeb1c4 –  —
  Linux    6.8 –                                       5.15.212
TIMELINE
  Jul 19  Reserved by CNA
  Jul 26  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 7 references · NVD status: Received
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0050   40.7     —
AFFECTED
  Product                          Versions  Fixed
  Microsoft Edge (Chromium-based)  - –       —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 26  Published (CNA: microsoft)
CWE-552 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
codexu NoteGen — NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  H    8.3   .0046   37.5     —
AFFECTED
  Product  Versions     Fixed
  NoteGen  unspecified  —
TIMELINE
  Jul 26  Reserved by CNA
  Jul 26  Published (CNA: JFROG)
CWE-78, CWE-276, CWE-1249 · CNA: JFROG · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
techjewel Fluent Forms Pro Add On Pack — Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0037   29.8     —
AFFECTED
  Product                       Versions     Fixed
  Fluent Forms Pro Add On Pack  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Jul 26  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0032   24.1     —
AFFECTED
  Product  Versions  Fixed
  spark    2.9.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-59, CWE-61 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
codexu NoteGen — NoteGen chat preview XSS via unsanitized AI/skill HTML rendering
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  N    8.1   .0032   24.0     —
AFFECTED
  Product  Versions     Fixed
  NoteGen  unspecified  —
TIMELINE
  Jul 26  Reserved by CNA
  Jul 26  Published (CNA: JFROG)
CWE-79 · CNA: JFROG · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0030   21.9     —
AFFECTED
  Product      Versions  Fixed
  openclaw-cn  0.2.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0029   20.9     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 26  Published (CNA: microsoft)
CWE-346 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0028   20.1     —
AFFECTED
  Product      Versions  Fixed
  openclaw-cn  0.2.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   L   L   L    1.3   .0023   13.6     —
AFFECTED
  Product       Versions    Fixed
  hermes-agent  2026.6.5 –  —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-266, CWE-284 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0023   13.2     —
AFFECTED
  Product   Versions  Fixed
  NanoClaw  2.0.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  L  L  N    5.4   .0014    3.8     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 26  Published (CNA: microsoft)
CWE-346 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Linux Linux — net: nexthop: Increase weight to u16
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0011    1.7     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    283a72a5599e80750699d2021830a294ed9ab3f3 –  —
  Linux    5.13 –                                      6.12
TIMELINE
  Jul 26  Reserved by CNA
  Jul 26  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 1 reference · NVD status: Received
nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0010    1.1     —
AFFECTED
  Product   Versions  Fixed
  NanoClaw  2.0.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-26 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.