Executive assessment
Today's brief leads with Multiple vulnerabilities in (Pwn2Own) Phoenix Contact CHARX SEC-3150. All 13 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — Multiple vulnerabilities in (Pwn2Own) Phoenix Contact CHARX SEC-3150
What changed: The cited advisories disclose: Jupicore External Control of Path Remote Code Execution Vulnerability; CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability; MQTT Service Server-Side Request Forgery Remote Code Execution Vulnerability; BackendURL WebSocket Command Injection Remote Code Execution Vulnerability; Missing Cryptographic Signature Remote Code Execution Vulnerability; CharxSystemConfigManager Configuration Injection Remote Code Execution Vulnerability. CVE coverage: CVE-2026-44103, CVE-2026-44099, CVE-2026-44091, CVE-2026-44098, CVE-2026-44104, CVE-2026-7849.
Technical evidence: CVE-2026-44104; CVSS v4.0 9.3; weakness ['CWE-347']; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-44104 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.zerodayinitiative.com](<https://www.zerodayinitiative.com/advisories/ZDI-26-520/>)
Finding 02 — Still active: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
Coverage status: First reported 2026-07-31; ongoing coverage.
What changed: CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity. Operators should map affected products to exposed services and repositories.
Technical evidence: CVE-2026-63077; CVSS v3.1 9.8; weakness ['CWE-502']; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-63077 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.rapid7.com](<https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity>)
Finding 03 — Still active: Multiple vulnerabilities in Phoenix Contact CHARX
Coverage status: First reported 2026-07-31; ongoing coverage.
What changed: The cited advisories disclose: SEC-3000 Command Injection Remote Code Execution Vulnerability; SEC-3150 OCPP Missing Authentication for Critical Function Authentication Bypass Vulnerability; SEC-3150 Failing Open Authentication Bypass Vulnerability; SEC-3150 user-applications Symlink Following Local Privilege Escalation Vulnerability; SEC-3150 Privilege Defined With Unsafe Actions Local Privilege Escalation Vulnerability; SEC-3150 Insertion of Sensitive Information into Log File Authentication Bypass Vulnerability; SEC-3150 user-applications Link Following Local Privilege Escalation Vulnerability; SEC-3000 Insertion of Sensitive Information into Log File Information Disclosure Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 charx-jupicore Missing Authentication Configuration Modification Vulnerability; SEC-3150 update2-upload Arbitrary File Upload Vulnerability; SEC-3150 ModBus Server Exposed Dangerous Function Denial-of-Service Vulnerability; SEC-3150 charx-system-config-manager Service CRLF Injection Firewall Bypass Vulnerability; SEC-3150 Race Condition Firewall Bypass Vulnerability. CVE coverage: CVE-2026-44095, CVE-2026-44101, CVE-2026-44094, CVE-2026-44093, CVE-2026-44096, CVE-2026-44105, CVE-2026-44106, CVE-2026-41032, CVE-2026-44090, CVE-2026-44100, CVE-2026-44097, CVE-2026-44107, CVE-2026-44092, CVE-2026-44108.
Technical evidence: CVE-2026-44101; CVSS v4.0 9.3; weakness ['CWE-306']; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-44101 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: www.zerodayinitiative.com](<https://www.zerodayinitiative.com/advisories/ZDI-26-521/>)
Finding 04 — CVE-2026-54910: FileBrowser Quantums path traversal issue in subtitle handler allows any…
What changed: FileBrowser Quantums path traversal issue in subtitle handler allows any authenticated user to read arbitrary files. Operators should map affected products to exposed services and repositories.
Technical evidence: CVE-2026-54910; CVSS v3.1 7.7; weakness ['CWE-22', 'CWE-23']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-54910 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-vvp7-h4fj-m28w>)
Finding 05 — Still active: Multiple vulnerabilities in WatchGuard FireWare OS
Coverage status: First reported 2026-07-31; ongoing coverage.
What changed: The cited advisories disclose: networkd networkwirelesskickoffusercb Stack-based Buffer Overflow Remote Code Execution Vulnerability; sigd compstartcb Directory Traversal Arbitrary File Creation Vulnerability. CVE coverage: CVE-2026-13050, CVE-2026-13054.
Technical evidence: CVE-2026-13050; CVSS v4.0 8.6; weakness ['CWE-787']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-13050 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
[Evidence source: www.zerodayinitiative.com](<https://www.zerodayinitiative.com/advisories/ZDI-26-500/>)
Finding 06 — CVE-2026-65835: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Gen…
What changed: Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation). Operators should map affected products to exposed services and repositories.
Technical evidence: CVE-2026-65835; CVSS v3.1 6.6; weakness ['CWE-269', 'CWE-863']; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-65835 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-jr6p-8pjj-mfx6>)
Finding 07 — CVE-2016-1000305: guard-livereload has a directory traversal vulnerability
What changed: guard-livereload has a directory traversal vulnerability. Operators should map affected products to exposed services and repositories.
Technical evidence: CVE-2016-1000305; CVSS v4.0 6.9; weakness ['CWE-22']; technical confidence Medium.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2016-1000305 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-g65v-27r3-5p6m>)
Finding 08 — CVE-2026-54785: gemini-bridge vulnerable to arbitrary local file read via consultgeminiwithfi…
What changed: gemini-bridge vulnerable to arbitrary local file read via consultgeminiwith_files inline mode. Operators should map affected products to exposed services and repositories.
Technical evidence: CVE-2026-54785; CVSS v3.1 6.2; weakness ['CWE-22', 'CWE-200']; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-54785 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-c5px-58j2-7fqp>)
Finding 09 — CVE-2026-54768: WPGraphQL has deprecated user field on SendPasswordResetEmailPayload that…
What changed: WPGraphQL has deprecated user field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design). Operators should map affected products to exposed services and repositories.
Technical evidence: CVE-2026-54768; CVSS v4.0 6.9; weakness ['CWE-204']; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-54768 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-jhh7-832h-f8hv>)
Finding 10 — CVE-2026-53573: core-geonetwork has an Open Redirect Bypass
What changed: core-geonetwork has an Open Redirect Bypass. Operators should map affected products to exposed services and repositories.
Technical evidence: CVE-2026-53573; CVSS v4.0 4.8; weakness ['CWE-601']; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-53573 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-pjp7-q6wp-97qx>)
Finding 11 — Still active: Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Coverage status: First reported 2026-07-30; ongoing coverage.
What changed: Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browsers renderer process.
Technical evidence: CVE-2026-10702; CVSS v3.1 4.3; weakness ['CWE-843']; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-10702 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/researchers-show-single-malicious.html>)
Finding 12 — Still active: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Coverage status: First reported 2026-07-31; ongoing coverage.
What changed: The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html>)
Finding 13 — Still active: Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Coverage status: First reported 2026-07-31; ongoing coverage.
What changed: Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on July 28, 144 days after reporting it to Microsoft.
Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: thehackernews.com](<https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html>)