Executive assessment
Today's brief leads with CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. All 12 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
What changed: The cited advisory discloses: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. CVE coverage: CVE-2026-63077.
Technical evidence: CVE-2026-63077; CVSS v3.1 9.8; weakness ['CWE-502']; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-63077 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.rapid7.com](<https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity>)
Finding 02 — Multiple vulnerabilities in Phoenix Contact CHARX
What changed: The cited advisories disclose: SEC-3150 Missing Cryptographic Signature Remote Code Execution Vulnerability; SEC-3150 Jupicore External Control of Path Remote Code Execution Vulnerability; SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability; SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability; SEC-3150 BackendURL WebSocket Command Injection Remote Code Execution Vulnerability; SEC-3150 CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability; SEC-3150 MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability; SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability; SEC-3150 update2-upload Arbitrary File Upload Vulnerability; SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 Failing Open Authentication Bypass Vulnerability; SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability; SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability; SEC-3150 Race Condition Firewall Bypass Vulnerability; SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability; SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability. CVE coverage: CVE-2026-44104, CVE-2026-44103, CVE-2026-44101, CVE-2026-44099, CVE-2026-44098, CVE-2026-7849, CVE-2026-44091, CVE-2026-44096, CVE-2026-44097, CVE-2026-41032, CVE-2026-44107, CVE-2026-44094, CVE-2026-44093, CVE-2026-44090, CVE-2026-44092, CVE-2026-44105, CVE-2026-44108, CVE-2026-44106, CVE-2026-44100.
Technical evidence: CVE-2026-44104; CVSS v4.0 9.3; weakness ['CWE-347']; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-44104 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-510/>)
Finding 03 — Still active: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Coverage status: First reported 2026-07-30; ongoing coverage.
What changed: The cited advisory discloses: Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw. CVE coverage: CVE-2026-16812.
Technical evidence: CVE-2026-16812; CVSS v3.1 10; weakness ['CWE-78']; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Action: Map CVE-2026-16812 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html>)
Finding 04 — Still active: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Coverage status: First reported 2026-07-30; ongoing coverage.
What changed: The cited advisory discloses: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory. CVE coverage: CVE-2026-59726.
Technical evidence: CVE-2026-59726; CVSS v3.1 10; weakness ['CWE-78', 'CWE-306', 'CWE-942']; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-59726 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html>)
Finding 05 — ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability…
What changed: The cited advisory discloses: ZDI-26-521: Phoenix Contact CHARX SEC-3000 Command Injection Remote Code Execution Vulnerability. CVE coverage: CVE-2026-44095.
Technical evidence: CVE-2026-44095; CVSS v4.0 8.5; weakness ['CWE-78']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-44095 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-521/>)
Finding 06 — Still active: Multiple vulnerabilities in WatchGuard FireWare OS
Coverage status: First reported 2026-07-30; ongoing coverage.
What changed: The cited advisories disclose: cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability; sigd compstartcb Directory Traversal Arbitrary File Creation Vulnerability. CVE coverage: CVE-2026-13053, CVE-2026-13054.
Technical evidence: CVE-2026-13053; CVSS v4.0 8.6; weakness ['CWE-787']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-13053 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-499/>)
Finding 07 — Still active: ZDI-26-500: WatchGuard FireWare OS networkd networkwirelesskickoffusercb Stack-based Buffer Overflow Remote Code Execution Vulnerability…
Coverage status: First reported 2026-07-30; ongoing coverage.
What changed: The cited advisory discloses: ZDI-26-500: WatchGuard FireWare OS networkd networkwirelesskickoffusercb Stack-based Buffer Overflow Remote Code Execution Vulnerability. CVE coverage: CVE-2026-13050.
Technical evidence: CVE-2026-13050; CVSS v4.0 8.6; weakness ['CWE-787']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-13050 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
[Evidence source: www.zerodayinitiative.com](<http://www.zerodayinitiative.com/advisories/ZDI-26-500/>)
Finding 08 — Still active: GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
Coverage status: First reported 2026-07-30; ongoing coverage.
What changed: The cited advisory discloses: GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193. CVE coverage: CVE-2022-39255, CVE-2024-45193.
Technical evidence: CVE-2022-39255; CVSS v3.1 8.6; weakness ['CWE-322', 'CWE-287']; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2022-39255 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-wchh-9x6h-7f6p>)
Finding 09 — Still active: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Coverage status: First reported 2026-07-30; ongoing coverage.
What changed: The cited advisory discloses: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser. CVE coverage: CVE-2026-10702.
Technical evidence: CVE-2026-10702; CVSS v3.1 4.3; weakness ['CWE-843']; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-10702 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/researchers-show-single-malicious.html>)
Finding 10 — Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
What changed: The cited advisory discloses: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation. CVE coverage: none.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html>)
Finding 11 — Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
What changed: The cited advisory discloses: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents. CVE coverage: none.
Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html>)
Finding 12 — Still active: Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Coverage status: First reported 2026-07-29; ongoing coverage.
What changed: The cited advisory discloses: Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock. CVE coverage: none.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.theregister.com](<https://www.theregister.com/security/2026/07/28/arista-patches-actively-exploited-velocloud-bug-as-cisa-puts-admins-on-the-clock/5279414>)