CVE Weekly Report — Week of Jul 13 – July 19, 2026
2026-W29
16
Total CVEs
3
Critical
7
High
0
Actively exploited
1 CVE is actively exploited (CISA KEV) this week. Patch these immediately: CVE-2026-63030
🔴 Critical CVEs (22)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-63030 | Wordpress | 9.8 | KEV | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which… | Jul 17 |
| CVE-2026-48358 | Magento | 9.1 | — | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary co… | Jul 14 |
| CVE-2026-48356 | Magento | 9.6 | — | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbi… | Jul 14 |
| CVE-2026-64089 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len ba… | Jul 19 |
| CVE-2026-64125 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting R… | Jul 19 |
| CVE-2026-64113 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast sourc… | Jul 19 |
| CVE-2026-53399 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4… | Jul 19 |
| CVE-2026-53398 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfs… | Jul 19 |
| CVE-2026-64142 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_l… | Jul 19 |
| CVE-2026-63800 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() W… | Jul 19 |
| CVE-2026-53384 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifi… | Jul 19 |
| CVE-2026-63795 | Linux | 10.0 | — | In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error … | Jul 19 |
| CVE-2026-64102 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow before s… | Jul 19 |
| CVE-2026-64132 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event(… | Jul 19 |
| CVE-2026-64136 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_fin… | Jul 19 |
| CVE-2026-64122 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_… | Jul 19 |
| CVE-2026-64150 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: release local_lock before re-… | Jul 19 |
| CVE-2026-13221 | Perl | 9.1 | — | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 6553… | Jul 13 |
| CVE-2026-64091 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans … | Jul 19 |
| CVE-2026-64160 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i_size… | Jul 19 |
| CVE-2026-64162 | Linux | 9.8 | — | In the Linux kernel, the following vulnerability has been resolved: idpf: fix read_dev_clk_lock spinlock init in idpf_p… | Jul 19 |
| CVE-2026-64106 | Linux | 9.0 | — | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-… | Jul 19 |
🟠 High CVEs (20)
| CVE | Product | CVSS | KEV | Description | Published |
|---|---|---|---|---|---|
| CVE-2026-47988 | Magento | 8.6 | — | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A… | Jul 14 |
| CVE-2026-47994 | Magento | 8.7 | — | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged… | Jul 14 |
| CVE-2026-63801 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: tipc: fix slab-use-after-free Read in tipc_aead_dec… | Jul 19 |
| CVE-2026-63796 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: ocfs2: reject oversized group bitmap descriptors o… | Jul 19 |
| CVE-2026-64138 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor d… | Jul 19 |
| CVE-2026-64093 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on c… | Jul 19 |
| CVE-2026-64088 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative tt_buff_len batadv_or… | Jul 19 |
| CVE-2026-64096 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: fix use-after-free in orig_node … | Jul 19 |
| CVE-2026-64178 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_ad… | Jul 19 |
| CVE-2026-64117 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: capture fast-RX rate before mesh re… | Jul 19 |
| CVE-2026-53369 | Linux | 8.4 | — | In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length … | Jul 19 |
| CVE-2026-63797 | Linux | 8.4 | — | In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix use-after-free on probe error path… | Jul 19 |
| CVE-2026-64153 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return value check… | Jul 19 |
| CVE-2026-63807 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Ensure hugepage is in by slot before … | Jul 19 |
| CVE-2026-64115 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix UAF when peer resets connection dur… | Jul 19 |
| CVE-2026-64104 | Linux | 8.7 | — | In the Linux kernel, the following vulnerability has been resolved: virt: sev-guest: Explicitly leak pages in unknown s… | Jul 19 |
| CVE-2026-64109 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read of tail->len in unix_stream_d… | Jul 19 |
| CVE-2026-53374 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocatio… | Jul 19 |
| CVE-2026-53375 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In… | Jul 19 |
| CVE-2026-64124 | Linux | 8.8 | — | In the Linux kernel, the following vulnerability has been resolved: net: devmem: reject dma-buf bind with non-page-alig… | Jul 19 |
