Thursday, July 30, 2026

Today's Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Today's Security Brief

Yesterday's disclosures were dominated by web platform and application infrastructure flaws, with unauthenticated remote code execution and authentication bypass affecting WordPress themes, Joomla extensions, Apache Airflow, and WebPros Plesk. The set includes 34 critical CVEs (CVSS 9.0+), up 48% from the prior day's 23, and 61 high-priority CVEs, up 5% from 58. Notable entries include CVE-2026-65883 (CVSS 10) in the Aimy Captcha-Less Form Guard plugin for Joomla, CVE-2026-58046 (CVSS 9.9) in WebPros Plesk, and CVE-2026-59243 (CVSS 9.8) in the Apache Airflow FAB provider. Beyond web platforms, the day extends into network edge and operational technology with Google Chrome (CVE-2026-16424, CVE-2026-16419), Phoenix Contact CHARX SEC-3150 EV charging controllers, and healthcare integration via the Care Everywhere Gateway. Three CVEs carry confirmed active exploitation (Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS), and with patch data recorded at 0% for this batch, teams should verify fix availability directly with vendors rather than assuming updates are published.

  • Aimy Captcha-Less Form Guard for Joomla (CVE-2026-65883) rates CVSS 10, the day's maximum-severity issue, alongside CVE-2026-58046 (CVSS 9.9) in WebPros Plesk
  • 34 critical CVEs (CVSS 9.0+), up 48% from 23 the prior day
  • 61 high-priority CVEs (CVSS 7.0-8.9), up 5% from 58 the prior day
  • Remote code execution and authentication bypass patterns concentrate in web platform components: Streamit WordPress theme, Cost Calculator Builder PRO, Admin and Site Enhancements (ASE) Pro, and the Apache Airflow FAB provider
  • Patch availability recorded at 0% across this batch; confirm fix status directly with vendors for Plesk, Airflow, Chrome, and Phoenix Contact CHARX SEC-3150 controllers
  • 3 CVEs have confirmed active exploitation, all in network edge infrastructure: Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS

Immediate action: Prioritize internet-facing network edge devices first: Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS all have confirmed exploitation, followed by hosting control planes (WebPros Plesk) and Apache Airflow deployments using the FAB provider. WordPress and Joomla site operators should audit for the affected Streamit theme, Cost Calculator Builder PRO, ASE Pro, and Aimy Captcha-Less Form Guard, and update or disable them. Patch availability is recorded at 0% for this batch, so check vendor advisories directly and apply access restrictions or network segmentation where fixes are not yet published.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation