| CVE-2026-63767: Deserialization of Untrusted Data | 9.8 Critical | 9.3 Critical | | | N/A | Jul 20, 2026 |
| CVE-2026-63766: OS Command Injection | 9.8 Critical | 9.3 Critical | | | N/A | Jul 20, 2026 |
| CVE-2026-53593: Unrestricted Upload of File with Dangerous Type | 8.8 High | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-53592: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | 4.6 Medium | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-53591: Improper Authentication | 8.6 High | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-44231: RT is an open source, enterprise-grade issue and ticket tracking system | 9.1 Critical | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-44230: RT is an open source, enterprise-grade issue and ticket tracking system | 6.1 Medium | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-44229: RT is an open source, enterprise-grade issue and ticket tracking system | 5.4 Medium | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-16337: Improper Privilege Management | N/A | 9.4 Critical | | | N/A | Jul 20, 2026 |
| CVE-2026-15788: Improper Link Resolution Before File Access | N/A | 5.6 Medium | | | N/A | Jul 20, 2026 |
| CVE-2026-64619: Use of Less Trusted Source | 7.5 High | 8.7 High | | | N/A | Jul 20, 2026 |
| CVE-2026-64194: Uncontrolled Recursion | N/A | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-64193: Eval Injection | N/A | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-63771: HTTP Response Splitting | 7.1 High | 6.0 Medium | | | N/A | Jul 20, 2026 |
| CVE-2026-63770: Use of Less Trusted Source | 7.5 High | 8.2 High | | | N/A | Jul 20, 2026 |
| CVE-2026-63769: Server-Side Request Forgery (SSRF) | 7.7 High | 6.3 Medium | | | N/A | Jul 20, 2026 |
| CVE-2026-63768: URL Redirection to Untrusted Site ('Open Redirect') | 4.3 Medium | 5.3 Medium | | | N/A | Jul 20, 2026 |
| CVE-2026-63731: Server-Side Request Forgery (SSRF) | 7.7 High | 6.3 Medium | | | N/A | Jul 20, 2026 |
| CVE-2026-63730: Server-Side Request Forgery (SSRF) | 5.0 Medium | 5.3 Medium | | | N/A | Jul 20, 2026 |
| CVE-2026-63108: Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows… | 8.8 High | 7.7 High | | | N/A | Jul 20, 2026 |
| CVE-2026-63107: Server-Side Request Forgery (SSRF) | 7.7 High | 6.3 Medium | | | N/A | Jul 20, 2026 |
| CVE-2026-62414: Improper Access Control | N/A | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-61901: The Joomla extension Hikashop is vulnerable to an open redirect. | N/A | N/A | | | N/A | Jul 20, 2026 |
| CVE-2026-61900: Unrestricted Upload of File with Dangerous Type | N/A | 10.0 Critical | | | N/A | Jul 20, 2026 |
| CVE-2026-61425: Authentication Bypass Using an Alternate Path or Channel | N/A | 9.4 Critical | | | N/A | Jul 20, 2026 |