Thursday, July 23, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Oracle Platform Security for Java and the Linux Kernel lead Thursday's disclosures, with two Oracle flaws (CVE-2026-60366 at CVSS 10 and CVE-2026-60369 at CVSS 9.9) and two kernel memory issues (CVE-2026-64035 and CVE-2026-64037, both CVSS 9.8) carrying near-maximum severity. The brief covers 11 critical CVEs, down 77% from the prior day's 48, and 29 high-priority CVEs, down 71% from 100. Additional critical entries affect the WordPress Kirki framework (CVE-2026-13147, CVSS 9.1) and the Perl Mojo::JWT library (CVE-2026-9537, CVSS 9.8). The disclosures span enterprise middleware, kernel-level components, and widely deployed web plugins, with remote code execution and authentication weaknesses recurring across the set. No patches were confirmed available at disclosure, so teams should track vendor advisories and prioritize exposed Oracle and Linux systems while validating fixes as they ship.

  • Oracle Platform Security for Java carries two critical flaws, CVE-2026-60366 (CVSS 10) and CVE-2026-60369 (CVSS 9.9)
  • Critical CVEs fell to 11, down 77% from the prior day's 48
  • High-priority CVEs fell to 29, down 71% from the prior day's 100
  • Linux Kernel accounts for two CVSS 9.8 issues (CVE-2026-64035, CVE-2026-64037); WordPress Kirki and Mojo::JWT add further critical exposure
  • Patch availability stood at 0% at disclosure, affecting Oracle middleware, Linux Kernel, and WordPress plugin deployments
  • Six CVEs show active exploitation, including flaws in SharePoint, Check Point SmartConsole, and WordPress Core

Immediate action: Prioritize Oracle Platform Security for Java and Linux Kernel systems, which hold the highest-severity flaws, and review WordPress installations running the Kirki framework. No patches were confirmed available at disclosure, so monitor vendor advisories and apply fixes for critical issues as soon as they are released.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation