Friday, July 24, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Friday's disclosures center on dbgate, which accounts for three critical vulnerabilities including CVE-2026-47668 at CVSS 10, alongside a cluster of high-impact WordPress plugin flaws affecting Participants Database, SAML SSO Login, and GoDAM media management. The day brought 38 critical CVEs, up 245% from the prior day's 11, and 80 high-priority CVEs, up 176% from 29. Named critical issues include CVE-2026-47668 (dbgate) and CVE-2026-59555 (Roland Barker Participants Database), both scored CVSS 10, plus CVE-2026-15981 (CVSS 9.8) in the cyberlord92 SAML SSO Login plugin. The activity skews heavily toward web application and WordPress ecosystem components, with authentication bypass and remote code execution among the recurring attack patterns. Vendor patches were not yet reflected in the source data at disclosure time (0% patch availability), so teams should prioritize compensating controls and monitor affected vendors for updates.

  • dbgate is the most affected product, with three critical CVEs including CVE-2026-47668 at CVSS 10
  • 38 critical CVEs disclosed, a 245% increase over the prior day's 11
  • 80 high-priority CVEs disclosed, a 176% increase over the prior day's 29
  • Authentication bypass and remote code execution feature across WordPress plugins including Participants Database, SAML SSO Login, and GoDAM
  • Patch availability stood at 0% in the source data at disclosure, requiring mitigation-first handling for critical items
  • 6 CVEs carry confirmed active-exploitation status across WordPress Core, Microsoft SharePoint, Check Point SmartConsole, and Langflow

Immediate action: Prioritize dbgate deployments and the affected WordPress plugins (Participants Database, SAML SSO Login, GoDAM), where multiple CVSS 9.0+ and two CVSS 10 flaws concentrate. With no vendor patches yet reflected for the critical items, apply available mitigations, restrict exposed interfaces, and monitor vendor advisories for fixes. Separately, verify remediation on the actively exploited SharePoint, Check Point SmartConsole, and WordPress Core issues.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation