Apache Traffic Server’s July 2026 security release patches dozens of flaws across its plugin surface, with the most severe letting unauthenticated attackers crash proxy tiers and bypass access controls.
An out-of-bounds write in Samba’s internal DNS server lets an unauthenticated attacker crash a domain controller’s DNS process with a single crafted TSIG packet.
Two unauthenticated flaws in IBM WebSphere Application Server traditional let remote attackers execute arbitrary code or escalate privileges through the administrative console.
A flaw in the chunked upload handler of WPForms Pro lets an unauthenticated attacker leave executable files on a WordPress server, opening a path to remote code execution.
A flaw in the Authentication Engine of Oracle Access Manager lets an unauthenticated attacker take over the single sign-on service that fronts an organization’s internal applications.
Oracle’s July 2026 Critical Patch Update fixes multiple flaws in WebLogic Server’s Core component, several letting an unauthenticated attacker fully take over the server over T3, IIOP, HTTP, and SOAP.
A PHP object injection flaw in PrestaShop’s ps_facetedsearch module lets an unauthenticated attacker smuggle a malicious object through a slider filter and achieve remote code execution on the storefront.
wp2shell chains a REST API batch-route confusion flaw with a SQL injection in WordPress core’s WP_Query, letting an unauthenticated attacker run code on a default install and take over the site.
A missing authentication flaw in on-premises Microsoft SharePoint Server lets an unauthenticated attacker escalate privileges over the network, a zero-day Microsoft confirms is already under active exploitation.
An unauthenticated file upload flaw in Balbooa Forms for Joomla lets any anonymous visitor drop a PHP file into a public folder, resulting in full remote code execution.