Friday, July 31, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Google Chrome accounted for the largest single cluster of critical vulnerabilities disclosed yesterday, alongside remote code execution flaws in the CodeIgniter4 PHP framework and several third-party web applications. The brief covers 41 critical vulnerabilities (up 21% from 34) and 74 high-priority vulnerabilities (up 21% from 61), for a total of 115 tracked CVEs. Notable entries include CVE-2026-17656 and CVE-2026-17670 (CVSS 9.6) in Google Chrome, CVE-2026-63223 (CVSS 9.8) in codeigniter4 CodeIgniter4, and CVE-2026-67208 (CVSS 9.8) in somta Juggle. Network security infrastructure also features prominently, with confirmed exploitation reported against Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS. Vendor patch data was unavailable for the tracked set at publication, so teams should verify fixed versions directly against vendor advisories before scheduling remediation.

  • Google Chrome and Chrome for iOS carry multiple CVSS 9.6 vulnerabilities, the largest critical cluster in this brief
  • 41 critical vulnerabilities (CVSS 9.0+), up 21% from 34 the prior day
  • 74 high-priority vulnerabilities (CVSS 7.0-8.9), up 21% from 61 the prior day
  • Remote code execution dominates the critical set, including CVE-2026-63223 in CodeIgniter4 (CVSS 9.8) and CVE-2026-67594 in yolanmees Spikster (CVSS 9.8)
  • Patch availability recorded at 0% across the tracked set, so fixed versions must be confirmed from vendor advisories
  • 3 vulnerabilities have confirmed active exploitation, affecting Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS (all CVSS 9.5)

Immediate action: Prioritize the three network edge and management products with confirmed exploitation (Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS), then push Chrome and Chrome for iOS updates through managed browser channels. Web application teams should review CodeIgniter4 deployments for CVE-2026-63223. Patch availability is reported at 0% for this set, so confirm fixed builds against vendor advisories and apply documented mitigations where no update exists yet.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation