Live Web Security Brief for July 28, 2026: APIs, WordPress, and Application Risk

Live Web Security Brief for July 28, 2026: APIs, WordPress, and Application Risk

Live web application intelligence for WordPress, APIs, authentication, authorization, injection flaws, dependencies, and browser-facing controls.

Live verification: This briefing was assembled from public CISA, NIST NVD, GitHub, Ubuntu, Microsoft, and other official publisher feeds checked on July 28, 2026 at 6:34 am IST. Existing posts are preserved and repeated source IDs are deduplicated.

Executive summary

The current source set produced 8 relevant updates for this briefing. It includes 3 CISA Known Exploited Vulnerabilities, 5 critical records, 0 high-severity records, and 0 official publisher updates. Severity alone is not treated as proof of exposure: teams should verify products, versions, reachability, privileges, and available mitigations.

Web exposure is determined by reachable routes, roles, data paths, plugin and framework versions, and compensating controls. Public exploitability and authentication requirements should guide the first response.

Top verified developments

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

CISA Known Exploited Vulnerabilities | July 27, 2026 | Known Exploited | Fortinet FortiOS

Source summary: Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-08-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Web Security review: Confirm whether the vulnerable route, plugin, framework, or API behavior is enabled and public.

Read the current source record

CVE-2026-60137: WordPress Core SQL Injection Vulnerability

CISA Known Exploited Vulnerabilities | July 21, 2026 | Known Exploited | WordPress Core

Source summary: WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-08-04. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Web Security review: Patch the component, test authentication and authorization boundaries, and review suspicious requests.

Read the current source record

CVE-2026-55971: Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects…

NIST National Vulnerability Database | July 27, 2026 | CRITICAL | CVSS 9.8

Source summary: Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to…

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Web Security review: Use a WAF as temporary risk reduction where appropriate, but keep the permanent software fix owned.

Read the current source record

CVE-2026-58023: Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache…

NIST National Vulnerability Database | July 27, 2026 | CRITICAL | CVSS 9.1

Source summary: Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade…

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Web Security review: Confirm whether the vulnerable route, plugin, framework, or API behavior is enabled and public.

Read the current source record

CVE-2026-58662: Improper Validation of Specified Quantity in Input, Out-of-bounds Read vulnerability in Apache…

NIST National Vulnerability Database | July 27, 2026 | CRITICAL | CVSS 9.1

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus