Latest Security Vulnerabilities
Wednesday July 22, 2026
Unclassified
CVE-2026-3821 SMC X14DBG-DAP/X14DBI 01.00.16.00 & 1.03.02.06 ATE via SMASH servicesCVE-2026-63047 Joomla Events Booking 5.05.8.1 Invoice Download Authorization Bypass
CVE-2026-63048 Joomla Page Builder CK 1.0.0-3.6.2 Arbitrary File Upload RCE
CVE-2026-45820 DDoS via infinite loop in fflate <0.8.3 unzipSync()
CVE-2026-12968 WP PlugIn: Product Addons & Options <1.6.15 Unauth SVG Upload Exec
CVE-2026-12987 PHP OI in Events Manager WP Plugin <7.3.7: DB Exfil via No-User-Account
CVE-2026-15802 WP Foodbakery v<=4.9 Arbitrary File Deletion via delete_locations_backup_file_callback
CVE-2026-14322 Timetics WP Plugin <1.0.57 Unauthenticated Booking Creation
CVE-2026-14551 ServerEye Agent <20.15 LP Escalation via SE3Recovery
And others...
Tuesday July 21, 2026
Google Chrome
CVE-2026-16413 ANGLE OOB write in Chrome <=150.0.7871.182, sandbox escape via crafted HTML pageCVE-2026-16418 V8 Stack Buffer Overflow in Chrome <150.0.7871.182 (Remote Code Exec)
CVE-2026-16419 Chrome ANGLE OOB Read/Write Sandbox Escape v<150.0.7871.182 (Android)
CVE-2026-16423 Chrome UI UAF before 150.0.7871.182
CVE-2026-16420 WebAudio Type Confusion Chrome <150.0.7871.182 Remote Code Execution
CVE-2026-16414 Chrome Chromecast sandbox escape via untrusted input (before 150.0.7871.182)
CVE-2026-16415 Google Chrome <=150.0.7871.182 Omnibox Spoof via Untrusted Input
CVE-2026-16416 Google Chrome <150.0.7871.182 Integer OverFlow in Chromecast Allows SandboxEsc.
CVE-2026-16417 Uninitialized Use in Skia (Chrome <150.0.7871.182)
And others...
Mozilla Firefox
CVE-2026-16402 Firefox Integer Overflow: ImageLib Component (Fixed in v153)CVE-2026-16394 Firefox DOM Mitigation Bypass in Security Component
CVE-2026-16372 Privilege Escalation in Firefox DOM Content Process Component
CVE-2026-16408 Mozilla Firefox: Integer Overflow in Audio/Video Playback Component
CVE-2026-16403 Address Bar Spoofing Issue in Firefox
CVE-2026-16399 Firefox DOM Navigation Site Isolation Vulnerability
CVE-2026-16391 Mozilla Firefox <153 ESR 140.13: IndexedDB Info Disclosure
CVE-2026-16388 Firefox Sandbox Escape: DOM Networking Component
CVE-2026-16376 DoS via WebGPU in Firefox
And others...
Unclassified
CVE-2026-3821 SMC X14DBG-DAP/X14DBI 01.00.16.00 & 1.03.02.06 ATE via SMASH servicesCVE-2026-63047 Joomla Events Booking 5.05.8.1 Invoice Download Authorization Bypass
CVE-2026-63048 Joomla Page Builder CK 1.0.0-3.6.2 Arbitrary File Upload RCE
CVE-2026-45820 DDoS via infinite loop in fflate <0.8.3 unzipSync()
CVE-2026-12968 WP PlugIn: Product Addons & Options <1.6.15 Unauth SVG Upload Exec
CVE-2026-12987 PHP OI in Events Manager WP Plugin <7.3.7: DB Exfil via No-User-Account
CVE-2026-15802 WP Foodbakery v<=4.9 Arbitrary File Deletion via delete_locations_backup_file_callback
CVE-2026-14322 Timetics WP Plugin <1.0.57 Unauthenticated Booking Creation
CVE-2026-14551 ServerEye Agent <20.15 LP Escalation via SE3Recovery
And others...
Oracle MySQL
CVE-2026-61093 Oracle MySQL 9.7.0-9.7.1 Server Optimizer DOS via Multi-ProtoCVE-2026-61096 Pluggable Auth: Unauth Integrity Impact in MySQL 8.4.x-8.4.10,8.0.x-8.0.47,9.7.x
CVE-2026-61109 DoS via JSON in MySQL Server/Cluster 8.4.x10.x
CVE-2026-61144 MySQL Server 9.7.0-9.7.1 Optimizer DoS Vulnerability
CVE-2026-61081 Oracle MySQL Server/Cluster 8.4.0-9.7.1 Performance Schema Unauthorized Read
CVE-2026-61094 Oracle MySQL Server/Cluster 8.4.0-10, 9.7.0-1 Replication RCE (High Priv)
CVE-2026-61108 MySQL Server 9.7.0-9.7.1 GIS DOS Attacks
CVE-2026-61128 MySQL 9.7.x Cluster Optimizer DoS via Net
Oracle Advanced Benefits
CVE-2026-61141 Oracle Advanced Benefits: HTTP Low-Priv RCE 12.2.7-12.2.15CVE-2026-61325 Oracle Advanced Benefits 12.2.15 Internal Ops Priv Escalation via HTTP
CVE-2026-61282 Oracle Advanced Benefits 12.2.4-12.2.15 Self Service Benefits Data Leak
CVE-2026-61323 Oracle AdvBenefits 12.2.15 Internal Ops HTTP Low-Priv Access
Oracle Agile Engineering Data Management
CVE-2026-61191 Oracle AEM DMS 6.2.1 Logon Host: Low-Priv Unauth Update & Partial DoSCVE-2026-61195 Oracle AgilE Data Mgmt 6.2.1 Core DoS via TCP
CVE-2026-61186 Oracle AEM Install v6.2.1 Unauth HTTP Remote DoS (CVE-2026-61186)
CVE-2026-61190 Oracle Agile Eng Data Mgmt 6.2.1 Install CVE: L-P Priv Exploitable via HTTP
Oracle Hrms
CVE-2026-61251 Oracle EBS HRMS Australia Payroll 12.2.3-12.2.15 CVE-2026-61251: Unauthorized AccessCVE-2026-62456 Oracle HRMS(UK) Int Ops CVE-2026-62456 v12.2.3-12.2.15 Remote Auth Bypass (AV:N)
CVE-2026-62521 Oracle HRMS US Payroll Unauthorized Access, 12.2.7-12.2.15
CVE-2026-62524 Oracle HRMS US Payroll General 12.2.312.2.15 HTTP Low-Priv Exploit
CVE-2026-62549 Oracle HRMS (UK) Abuse: HTTP LPE <12.2.15 (CVSS 9.6)
CVE-2026-62557 Oracle HRMS (UK) Pre-12.2.15 Unauth HTTP RCE UK Payroll
CVE-2026-62560 Oracle HRMS (Norway) Internal Ops HTTP Remote Auth Bypass 12.2.3-12.2.15
CVE-2026-62561 Oracle HRMS (US) 12.2.3-12.2.15 Internal Ops Privilege Escalation
CVE-2026-62567 Oracle HRMS (UK) 12.2.3-12.2.15 Low Privilege HTTP Attack via UK Payroll
And others...
Oracle Product Hub
CVE-2026-61274 Oracle Product Hub Item Catalog RCE via HTTP (12.2.3-12.2.15)CVE-2026-61275 Oracle Product Hub 12.2.3-12.2.15 RBS Privilege Escalation
CVE-2026-61311 Oracle EBS Product Hub Internal Ops CVE-2026-61311 (12.2.3-12.2.15) for HTTP
CVE-2026-61310 Oracle Product Hub Int Ops v12.2.-12.2.15: HTTP Low-Priv PWN CVE-2026-61310
Elasticsearch
CVE-2026-56144 Elasticsearch Ingest Simulation Auth Bypass (CWE-863)CVE-2026-63136 Elasticsearch CVE-2026-63136: Uncontrolled Resource Consumption (CWE-400)
CVE-2026-63144 Elasticsearch Recursion DoS via Malicious Query (CVE-2026-63144)
CVE-2026-63263 Elasticsearch ES|QL CPU Exhaustion via Exponential Data Expansion
CVE-2026-63140 Elasticsearch DoS via Assertion Failure in Query Parsing
CVE-2026-56145 Elasticsearch Uncontrolled Resource Consumption via EQL Query
Elastic Kibana
CVE-2026-63139 Kibana Canvas Authenticated DoS via Uncontrolled Resource ConsumptionCVE-2026-63143 Missing Auth in Kibana Unauthorized Data Disclosure
CVE-2026-63142 Kibana Reporting: Auth Bypass via Missing Disallowed Inputs (CWE-184)
CVE-2026-63260 Kibana Uncontrolled Resource Consumption via Oversized Payload DoS
CVE-2026-56147 Kibana Auth Bypass via UserControlled Key (CWE639)