ELEVATED 8 min read 1 Aug 2026

Multiple vulnerabilities in (Pwn2Own) Phoenix Contact CHARX SEC-3150 Leads Today's Security Review

Executive assessment Today's brief leads with Multiple vulnerabilities in (Pwn2Own) Phoenix Contact CHARX SEC-3150. All 13 selected findings retain their own technical scope, action, observed status, and evidence limits.

Key findings
01
Multiple vulnerabilities in (Pwn2Own) Phoenix Contact CHARX SEC-3150
CRITICAL
The cited advisories disclose: Jupicore External Control of Path Remote Code Execution Vulnerability; CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability; MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability; BackendURL WebSocket Command Injection Remote Code Execution Vulnerability; Missing Cryptographic Signature Remote Code Execution Vulnerability; CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability.
02
Still active: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
CRITICAL
First reported 2026-07-31; ongoing coverage. CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. Operators should map affected products to exposed services and repositories.
03
Still active: Multiple vulnerabilities in Phoenix Contact CHARX
CRITICAL
First reported 2026-07-31; ongoing coverage. The cited advisories disclose: SEC-3000 Command Injection Remote Code Execution Vulnerability; SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability; SEC-3150 Failing Open Authentication Bypass Vulnerability;
04
CVE-2026-54910: FileBrowser Quantums path traversal issue in subtitle handler allows any…
HIGH
FileBrowser Quantums path traversal issue in subtitle handler allows any authenticated user to read arbitrary files. Operators should map affected products to exposed services and repositories. The assigned identifier is CVE-2026-54910.
05
Still active: Multiple vulnerabilities in WatchGuard FireWare OS
HIGH
First reported 2026-07-31; ongoing coverage. The cited advisories disclose: networkd networkwirelesskickoffusercb Stack-based Buffer Overflow Remote Code Execution Vulnerability; sigd compstart_cb Directory Traversal Arbitrary File Creation Vulnerability.
06
CVE-2026-65835: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Gen…
MEDIUM
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation). Operators should map affected products to exposed services and repositories. The assigned identifier is CVE-2026-65835.
07
CVE-2016-1000305: guard-livereload has a directory traversal vulnerability
MEDIUM
guard-livereload has a directory traversal vulnerability. Operators should map affected products to exposed services and repositories. The assigned identifier is CVE-2016-1000305.
08
CVE-2026-54785: gemini-bridge vulnerable to arbitrary local file read via consultgeminiwith_fi…
MEDIUM
gemini-bridge vulnerable to arbitrary local file read via consultgeminiwith_files inline mode. Operators should map affected products to exposed services and repositories. The assigned identifier is CVE-2026-54785.
09
CVE-2026-54768: WPGraphQL has deprecated user field on SendPasswordResetEmailPayload that…
MEDIUM
WPGraphQL has deprecated user field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design). Operators should map affected products to exposed services and repositories. The assigned identifier is CVE-2026-54768.
10
CVE-2026-53573: core-geonetwork has an Open Redirect Bypass
MEDIUM
core-geonetwork has an Open Redirect Bypass. Operators should map affected products to exposed services and repositories. The assigned identifier is CVE-2026-53573.
11
Still active: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
MEDIUM
First reported 2026-07-30; ongoing coverage. Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.
12
Still active: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
INFO
First reported 2026-07-31; ongoing coverage. The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S.
13
Still active: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
INFO
First reported 2026-07-31; ongoing coverage. Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.

Executive assessment

Today's brief leads with Multiple vulnerabilities in (Pwn2Own) Phoenix Contact CHARX SEC-3150. All 13 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Multiple vulnerabilities in (Pwn2Own) Phoenix Contact CHARX SEC-3150

What changed: The cited advisories disclose: Jupicore External Control of Path Remote Code Execution Vulnerability; CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability; MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability; BackendURL WebSocket Command Injection Remote Code Execution Vulnerability; Missing Cryptographic Signature Remote Code Execution Vulnerability; CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability. CVE coverage: CVE-2026-44103, CVE-2026-44099, CVE-2026-44091, CVE-2026-44098, CVE-2026-44104, CVE-2026-7849.

Technical evidence: CVE-2026-44104; CVSS v4.0 9.3; weakness ['CWE-347']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-44104 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.zerodayinitiative.com](<https://www.zerodayinitiative.com/advisories/ZDI-26-520/>)

Finding 02 — Still active: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Coverage status: First reported 2026-07-31; ongoing coverage.

What changed: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. Operators should map affected products to exposed services and repositories.

Technical evidence: CVE-2026-63077; CVSS v3.1 9.8; weakness ['CWE-502']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-63077 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.rapid7.com](<https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity>)

Finding 03 — Still active: Multiple vulnerabilities in Phoenix Contact CHARX

Coverage status: First reported 2026-07-31; ongoing coverage.

What changed: The cited advisories disclose: SEC-3000 Command Injection Remote Code Execution Vulnerability; SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability; SEC-3150 Failing Open Authentication Bypass Vulnerability; SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability; SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability; SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability; SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability; SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability; SEC-3150 update2-upload Arbitrary File Upload Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability; SEC-3150 Race Condition Firewall Bypass Vulnerability. CVE coverage: CVE-2026-44095, CVE-2026-44101, CVE-2026-44094, CVE-2026-44093, CVE-2026-44096, CVE-2026-44105, CVE-2026-44106, CVE-2026-41032, CVE-2026-44090, CVE-2026-44100, CVE-2026-44097, CVE-2026-44107, CVE-2026-44092, CVE-2026-44108.

Technical evidence: CVE-2026-44101; CVSS v4.0 9.3; weakness ['CWE-306']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-44101 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.zerodayinitiative.com](<https://www.zerodayinitiative.com/advisories/ZDI-26-521/>)

Finding 04 — CVE-2026-54910: FileBrowser Quantums path traversal issue in subtitle handler allows any…

What changed: FileBrowser Quantums path traversal issue in subtitle handler allows any authenticated user to read arbitrary files. Operators should map affected products to exposed services and repositories.

Technical evidence: CVE-2026-54910; CVSS v3.1 7.7; weakness ['CWE-22', 'CWE-23']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54910 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-vvp7-h4fj-m28w>)

Finding 05 — Still active: Multiple vulnerabilities in WatchGuard FireWare OS

Coverage status: First reported 2026-07-31; ongoing coverage.

What changed: The cited advisories disclose: networkd networkwirelesskickoffusercb Stack-based Buffer Overflow Remote Code Execution Vulnerability; sigd compstartcb Directory Traversal Arbitrary File Creation Vulnerability. CVE coverage: CVE-2026-13050, CVE-2026-13054.

Technical evidence: CVE-2026-13050; CVSS v4.0 8.6; weakness ['CWE-787']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-13050 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.zerodayinitiative.com](<https://www.zerodayinitiative.com/advisories/ZDI-26-500/>)

Finding 06 — CVE-2026-65835: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Gen…

What changed: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation). Operators should map affected products to exposed services and repositories.

Technical evidence: CVE-2026-65835; CVSS v3.1 6.6; weakness ['CWE-269', 'CWE-863']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-65835 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-jr6p-8pjj-mfx6>)

Finding 07 — CVE-2016-1000305: guard-livereload has a directory traversal vulnerability

What changed: guard-livereload has a directory traversal vulnerability. Operators should map affected products to exposed services and repositories.

Technical evidence: CVE-2016-1000305; CVSS v4.0 6.9; weakness ['CWE-22']; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2016-1000305 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-g65v-27r3-5p6m>)

Finding 08 — CVE-2026-54785: gemini-bridge vulnerable to arbitrary local file read via consultgeminiwithfi…

What changed: gemini-bridge vulnerable to arbitrary local file read via consultgeminiwith_files inline mode. Operators should map affected products to exposed services and repositories.

Technical evidence: CVE-2026-54785; CVSS v3.1 6.2; weakness ['CWE-22', 'CWE-200']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54785 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-c5px-58j2-7fqp>)

Finding 09 — CVE-2026-54768: WPGraphQL has deprecated user field on SendPasswordResetEmailPayload that…

What changed: WPGraphQL has deprecated user field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design). Operators should map affected products to exposed services and repositories.

Technical evidence: CVE-2026-54768; CVSS v4.0 6.9; weakness ['CWE-204']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-54768 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-jhh7-832h-f8hv>)

Finding 10 — CVE-2026-53573: core-geonetwork has an Open Redirect Bypass

What changed: core-geonetwork has an Open Redirect Bypass. Operators should map affected products to exposed services and repositories.

Technical evidence: CVE-2026-53573; CVSS v4.0 4.8; weakness ['CWE-601']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-53573 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-pjp7-q6wp-97qx>)

Finding 11 — Still active: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

Coverage status: First reported 2026-07-30; ongoing coverage.

What changed: Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browsers renderer process.

Technical evidence: CVE-2026-10702; CVSS v3.1 4.3; weakness ['CWE-843']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-10702 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/researchers-show-single-malicious.html>)

Finding 12 — Still active: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Coverage status: First reported 2026-07-31; ongoing coverage.

What changed: The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html>)

Finding 13 — Still active: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Coverage status: First reported 2026-07-31; ongoing coverage.

What changed: Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.

Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html>)

cve-2016-1000305cve-2026-10702cve-2026-13050cve-2026-53573cve-2026-54768cve-2026-54785cve-2026-54910cve-2026-63077cve-2026-65835

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.