Tuesday, July 28, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Web-facing application software dominated Tuesday's disclosures, with remote code execution and authentication bypass issues reported in pheditor, vBulletin, phpMyFAQ, Erlang OTP, and a broad set of WordPress plugins including Realtyna Organic IDX and FacturaONE for WooCommerce. The day brought 30 critical CVEs (CVSS 9.0+) and 91 high-priority CVEs, up from 6 and 18 the prior day, a roughly fourfold increase in both categories across 121 total records. CVE-2026-48030 (CVSS 9.9, pheditor) and CVE-2026-55579 (CVSS 9.8, pheditor) sit at the top of the range, followed by CVE-2026-61511 (CVSS 9.8, vBulletin) and CVE-2026-66398 (CVSS 9.4, phpMyFAQ). Content management platforms, e-commerce plugins, and self-hosted collaboration tools carry most of the critical weight, while five vulnerabilities have confirmed active exploitation, including CVE-2026-16812 (CVSS 10.0) in Arista VeloCloud Orchestrator On-Prem and CVE-2026-50522 in Microsoft SharePoint. No patch data was recorded for this set, so treat remediation status as unconfirmed and verify fix availability directly with each vendor before planning rollout.

  • pheditor accounts for two of the day's highest-scoring issues: CVE-2026-48030 (CVSS 9.9) and CVE-2026-55579 (CVSS 9.8), both in a web-exposed editing component
  • 30 critical CVEs (CVSS 9.0+), a 400% increase over the prior day's 6
  • 91 high-priority CVEs (CVSS 7.0-8.9), a 406% increase over the prior day's 18
  • Remote code execution and authentication bypass patterns lead the set, affecting vBulletin (CVE-2026-61511, CVSS 9.8), phpMyFAQ (CVE-2026-66398, CVSS 9.4), and Erlang OTP (CVE-2026-55953, CVSS 9.1)
  • WordPress plugin flaws form a large share of the critical tier, including Realtyna Organic IDX (CVE-2026-13714, CVSS 9.8) and FacturaONE for WooCommerce (CVE-2026-14289, CVSS 9.0)
  • Patch availability is recorded at 0% for this set; five CVEs show confirmed active exploitation, spanning Arista VeloCloud Orchestrator On-Prem, Microsoft SharePoint, Check Point SmartConsole, WordPress Core, and Fortinet FortiOS

Immediate action: Prioritize internet-facing WordPress installations and their plugin inventory, along with vBulletin, phpMyFAQ, and pheditor deployments, since these carry the highest-scoring remote code execution and authentication bypass issues. Separately, review exposure to the five actively exploited products (Arista VeloCloud Orchestrator On-Prem, Microsoft SharePoint, Check Point SmartConsole, WordPress Core, and Fortinet FortiOS) and apply vendor updates or mitigations promptly. No patch availability was recorded for this batch, so confirm fix status with each vendor and apply access restrictions or WAF rules where updates are not yet published.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation