boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, July 26, 2026 · all times UTC← 2026-07-25 · archive · 2026-07-27 →

15 CVEs published, led by Microsoft (3).

15 CVEs published July 26, 2026: 1 critical, 7 high, 1 medium, 6 low; 0 in the KEV catalog at press time; 1 with a public exploit reference; 0 awaiting enrichment.

Standings

League
MTDYTD2025 same span2025 full
CVEs published79622034513692564
KEV catalog size1671

848 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux8042286203121163512730.17.8.0014+291 ▲
microsoft663142910398332014380322.27.8.0041+443 ▲
google1191383156629556397460.47.8.0024-588 ▼
red hat1173091612115418400.06.5.0025+9 ▲
apple31021256729476.96.5.0030-12 ▼
canonical72738115000.05.6.0011+1 ▲
suse82141241000.08.5.0033+4 ▲
freebsd01601240000.07.8.0015-2 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco163961690961230.87.5.0050+6 ▲
ubiquiti2536142110438.38.8.0036+17 ▲
palo alto networks1425021471428.04.7.0021+5 ▲
netgear62300221800.04.6.0022-11 ▼
fortinet14223610028522.76.7.0036+12 ▲
f58175830715.98.6.0057+2 ▲
checkpoint31236303216.77.7.04450
vmware81117212200.08.0.0031+5 ▲
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache1032565510287114010.47.5.0048-1 ▼
mozilla7112751423401300.08.1.0029+22 ▲
drupal465165355512.05.9.0018+46 ▲
gitlab74005276425.04.7.0024-17 ▼
github5111280000.06.0.0026+4 ▲
docker070520100.08.2.0016-4 ▼
wordpress22101052100.07.9.8435+2 ▲
kubernetes110001000.02.4.0024+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091379342653322614030.28.1.0032+866 ▲
adobe952412610310547541.77.6.0021-37 ▼
ibm371615254550700.07.5.0026+5 ▲
progress283762470900.07.5.0032+23 ▲
solarwinds15221523011418.29.1.0043+12 ▲
zohocorp362220000.07.8.0109+2 ▲
veeam152300400.08.6.00400
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0025+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link82105962614.85.5.0069-1 ▼
siemens7161870100.07.6.00190
abb170430000.07.2.0018-5 ▼
hikvision5603202116.77.2.0024+5 ▲
schneider electric060420100.07.8.0024-6 ▼
moxa050320000.07.0.0029-5 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.0026+12 ▲
openclaw441110583914000.07.0.0022-17 ▼
dell4399447443211.07.0.0020+5 ▲
capgo2283242381000.07.1.0028-24 ▼
nvidia41801252160000.07.8.0019+35 ▲
imagemagick3374155612300.05.3.0017-2 ▼
spring073231391000.06.5.0024-72 ▼
itsourcecode1871001952000.02.1.0020-4 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-63030.956099.99.8
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-56290.832599.710.0
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
CVE-2026-56291.760799.510.0
CVE-2026-15409.742299.410.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-5016010.0.1775
CVE-2026-898510.0.0660
CVE-2026-4827610.0.0505
CVE-2026-651610.0.0473
Most disclosures (vendor)
VendorCVEs
oracle1109
linux805
microsoft664
google502
red hat137
apache120
adobe105
ibm80
mozilla72
sourcecodester61
Most KEV additions (YTD)
VendorKEV
microsoft32
cisco12
apple7
google6
fortinet5
ivanti5
adobe4
solarwinds4
synacor4
langflow3
Most-affected ecosystems
EcosystemAdvisories
Maven63
PyPI5
NuGet3
npm3
Packagist1
crates.io1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2021-27137DD-WRT0
CVE-2023-4346KNX Association0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-25089Fortinet0
CVE-2026-39808Fortinet0
CVE-2026-45659Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171712
CVE-2021-27102Accellion2021-11-171712
CVE-2021-27101Accellion2021-11-171712
CVE-2021-27103Accellion2021-11-171712
CVE-2021-21017Adobe2021-11-171712
CVE-2021-28550Adobe2021-11-171712
CVE-2021-42013Apache2021-11-171712
CVE-2021-41773Apache2021-11-171712
CVE-2021-30858Apple2021-11-171712
CVE-2021-30860Apple2021-11-171712

Transactions

EXPLOIT PUBLISHEDCVE-2026-16735 (release-it conventional-changelog). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65700 (h2oai h2ogpt). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-65707 (likeadmin-likeshop likeshop). Public exploit reference added.

DUE DATE PASSEDCVE-2026-16232 (checkpoint Quantum Security Management). CISA remediation deadline was July 25, 2026; still in catalog.

DUE DATE PASSEDCVE-2026-50522 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 25, 2026; still in catalog.

ENRICHEDCVE-2020-19909. Received CVSS 3.3 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

15 CVEs published. 15 box scores, 0 table rows — nothing truncated.

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0092   57.6     —
AFFECTED
  Product                          Versions  Fixed
  Microsoft Edge (Chromium-based)  - –       —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 26  Published (CNA: microsoft)
CWE-552 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Linux Linux — net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    172ba7d46c202e679f3ccb10264c67416aaeb1c4 –  —
  Linux    6.8 –                                       5.15.212
TIMELINE
  Jul 19  Reserved by CNA
  Jul 26  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 7 references · NVD status: Received
codexu NoteGen — NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   R  C  H  H  H    8.3   .0046   37.9     —
AFFECTED
  Product  Versions     Fixed
  NoteGen  unspecified  —
TIMELINE
  Jul 26  Reserved by CNA
  Jul 26  Published (CNA: JFROG)
CWE-78, CWE-276, CWE-1249 · CNA: JFROG · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  C  H  N  N    7.4   .0043   36.0     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 26  Published (CNA: microsoft)
CWE-346 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
koxudaxi datamodel-code-generator — datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   N   A   H   H   H    7.5   .0042   35.5     —
AFFECTED
  Product                   Versions     Fixed
  datamodel-code-generator  unspecified  —
TIMELINE
  Jul 17  Reserved by CNA
  Jul 26  Published (CNA: VulnCheck)
CWE-94 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Deferred
techjewel Fluent Forms Pro Add On Pack — Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0038   31.5     —
AFFECTED
  Product                       Versions     Fixed
  Fluent Forms Pro Add On Pack  unspecified  —
TIMELINE
  Jul 16  Reserved by CNA
  Jul 26  Published (CNA: Wordfence)
CWE-502 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0032   24.8     —
AFFECTED
  Product  Versions  Fixed
  spark    2.9.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-59, CWE-61 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   N   N    2.1   .0032   24.3     —
AFFECTED
  Product      Versions  Fixed
  openclaw-cn  0.2.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-200, CWE-284 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
codexu NoteGen — NoteGen chat preview XSS via unsanitized AI/skill HTML rendering
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  H  H  N    8.1   .0030   22.7     —
AFFECTED
  Product  Versions     Fixed
  NoteGen  unspecified  —
TIMELINE
  Jul 26  Reserved by CNA
  Jul 26  Published (CNA: JFROG)
CWE-79 · CNA: JFROG · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   N   L   N   L   L   L    1.3   .0023   14.1     —
AFFECTED
  Product       Versions    Fixed
  hermes-agent  2026.6.5 –  —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-266, CWE-284 · CNA: VulDB · CVSS v4.0 · 9 references · NVD status: Deferred
mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0023   13.8     —
AFFECTED
  Product      Versions  Fixed
  openclaw-cn  0.2.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-918 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    2.1   .0021   12.1     —
AFFECTED
  Product   Versions  Fixed
  NanoClaw  2.0.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Microsoft Edge (Chromium-based) Spoofing Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   R  U  L  L  N    5.4   .0021   11.8     —
AFFECTED
  Product                          Versions   Fixed
  Microsoft Edge (Chromium-based)  1.0.0.0 –  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 26  Published (CNA: microsoft)
CWE-346 · CNA: microsoft · CVSS v3.1 · 1 reference · NVD status: Analyzed
Linux Linux — net: nexthop: Increase weight to u16
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0011    1.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    283a72a5599e80750699d2021830a294ed9ab3f3 –  —
  Linux    5.13 –                                      6.12
TIMELINE
  Jul 26  Reserved by CNA
  Jul 26  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 1 reference · NVD status: Received
nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   L   L   N   L   N   L   L   L    1.9   .0010    1.1     —
AFFECTED
  Product   Versions  Fixed
  NanoClaw  2.0.0 –   —
TIMELINE
  Jul 25  Reserved by CNA
  Jul 26  Published (CNA: VulDB)
CWE-266, CWE-285 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-26 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion.