{
  "day": "2026-07-26",
  "boundary": "UTC calendar day",
  "published_count": 15,
  "by_severity": {
    "CRITICAL": 1,
    "HIGH": 7,
    "MEDIUM": 1,
    "LOW": 6
  },
  "kev_count": 0,
  "exploit_reference_count": 1,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-57990",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00923,
      "epss_percentile": 0.57586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-552",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57990"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-64530",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00509,
      "epss_percentile": 0.41292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64530"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-17497",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codexu",
      "product": "NoteGen",
      "cwe": "CWE-78",
      "title": "NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17497"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-57989",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00429,
      "epss_percentile": 0.35957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-346",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57989"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-63720",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-94",
      "title": "datamodel-code-generator Code Injection via Unvalidated customBasePath Schema Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63720"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-15962",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "techjewel",
      "product": "Fluent Forms Pro Add On Pack",
      "cwe": "CWE-502",
      "title": "Fluent Forms Pro Add On Pack <= 6.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15962"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-17459",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00319,
      "epss_percentile": 0.2475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perwendel",
      "product": "spark",
      "cwe": "CWE-59",
      "title": "perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17459"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-17457",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00315,
      "epss_percentile": 0.2435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mf-yang",
      "product": "openclaw-cn",
      "cwe": "CWE-200",
      "title": "mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17457"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-17496",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codexu",
      "product": "NoteGen",
      "cwe": "CWE-79",
      "title": "NoteGen chat preview XSS via unsanitized AI/skill HTML rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17496"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-17432",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0023,
      "epss_percentile": 0.14112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-266",
      "title": "NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17432"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-17458",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mf-yang",
      "product": "openclaw-cn",
      "cwe": "CWE-918",
      "title": "mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17458"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-17434",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "NanoClaw",
      "cwe": "CWE-266",
      "title": "nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17434"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-57978",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-346",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57978"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2024-14040",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: nexthop: Increase weight to u16",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14040"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-17433",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "NanoClaw",
      "cwe": "CWE-266",
      "title": "nanocoai NanoClaw MCP Server Approval chat-sdk-bridge.ts createChatSdkBridge.setup improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17433"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16735",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16735 (release-it conventional-changelog). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65700",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65700 (h2oai h2ogpt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65707",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65707 (likeadmin-likeshop likeshop). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-16232",
      "detail": "DUE DATE PASSED — CVE-2026-16232 (checkpoint Quantum Security Management). CISA remediation deadline was July 25, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-50522",
      "detail": "DUE DATE PASSED — CVE-2026-50522 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 25, 2026; still in catalog."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2020-19909",
      "detail": "ENRICHED — CVE-2020-19909. Received CVSS 3.3 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
