CVE Weekly Report — Week of Jul 13 – July 19, 2026

2026-W29

16
Total CVEs
3
Critical
7
High
0
Actively exploited

1 CVE is actively exploited (CISA KEV) this week. Patch these immediately: CVE-2026-63030

🔴 Critical CVEs (22)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-63030Wordpress9.8KEVWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which…Jul 17
CVE-2026-48358Magento9.1Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co…Jul 14
CVE-2026-48356Magento9.6Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi…Jul 14
CVE-2026-64089Linux9.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len ba…Jul 19
CVE-2026-64125Linux9.8In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting R…Jul 19
CVE-2026-64113Linux9.8In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast sourc…Jul 19
CVE-2026-53399Linux9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4…Jul 19
CVE-2026-53398Linux9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfs…Jul 19
CVE-2026-64142Linux9.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_l…Jul 19
CVE-2026-63800Linux9.8In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() W…Jul 19
CVE-2026-53384Linux9.8In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifi…Jul 19
CVE-2026-63795Linux10.0In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error …Jul 19
CVE-2026-64102Linux9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow before s…Jul 19
CVE-2026-64132Linux9.8In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event(…Jul 19
CVE-2026-64136Linux9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_fin…Jul 19
CVE-2026-64122Linux9.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_…Jul 19
CVE-2026-64150Linux9.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-…Jul 19
CVE-2026-13221Perl9.1Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 6553…Jul 13
CVE-2026-64091Linux9.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans …Jul 19
CVE-2026-64160Linux9.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i_size…Jul 19
CVE-2026-64162Linux9.8In the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_clk_lock spinlock init in idpf_p…Jul 19
CVE-2026-64106Linux9.0In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-…Jul 19

🟠 High CVEs (20)

CVEProductCVSSKEVDescriptionPublished
CVE-2026-47988Magento8.6Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A…Jul 14
CVE-2026-47994Magento8.7Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged…Jul 14
CVE-2026-63801Linux8.8In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aead_dec…Jul 19
CVE-2026-63796Linux8.8In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group bitmap descriptors o…Jul 19
CVE-2026-64138Linux8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor d…Jul 19
CVE-2026-64093Linux8.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on c…Jul 19
CVE-2026-64088Linux8.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative tt_buff_len batadv_or…Jul 19
CVE-2026-64096Linux8.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_node …Jul 19
CVE-2026-64178Linux8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_ad…Jul 19
CVE-2026-64117Linux8.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: capture fast-RX rate before mesh re…Jul 19
CVE-2026-53369Linux8.4In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length …Jul 19
CVE-2026-63797Linux8.4In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free on probe error path…Jul 19
CVE-2026-64153Linux8.8In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return value check…Jul 19
CVE-2026-63807Linux8.8In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot before …Jul 19
CVE-2026-64115Linux8.8In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix UAF when peer resets connection dur…Jul 19
CVE-2026-64104Linux8.7In the Linux kernel, the following vulnerability has been resolved: virt: sev-guest: Explicitly leak pages in unknown s…Jul 19
CVE-2026-64109Linux8.8In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read of tail->len in unix_stream_d…Jul 19
CVE-2026-53374Linux8.8In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocatio…Jul 19
CVE-2026-53375Linux8.8In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In…Jul 19
CVE-2026-64124Linux8.8In the Linux kernel, the following vulnerability has been resolved: net: devmem: reject dma-buf bind with non-page-alig…Jul 19

📦 Most affected products