Daily briefing · July 1, 2026
368 New CVEs on July 1: Perfect-10 Hoppscotch Flaw, WordPress Admin Takeover, and Four Chrome Sandbox Escapes Dominate
July 1, 2026 brought 368 new vulnerabilities, 54 of them critical — with no active exploitation confirmed yet, but several entries carry maximum-severity scores and high exploitation potential. A perfect CVSS 10.0 mass assignment flaw in Hoppscotch self-hosted deployments leads the day, flanked by two unauthenticated privilege escalation bugs in widely deployed WordPress and AI infrastructure, and a cluster of four use-after-free sandbox escape vulnerabilities in Google Chrome.
Today’s brief
- Hoppscotch scores CVSS 10.0: an unauthenticated endpoint in self-hosted backends allows mass assignment, no credentials required.
- WordPress SMS Alert plugin (≤3.9.5) enables full admin account takeover via password reset without identity verification.
- NVIDIA AIStore authentication bypass can lead to privilege escalation, data tampering, and denial of service.
- Four use-after-free bugs in Chrome (Skia, Dawn, ANGLE) allow remote sandbox escape via a crafted web page — update immediately.
54
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
A CVSS 10.0 mass assignment vulnerability in Hoppscotch self-hosted backends (≤2026.4.1) exposes an unauthenticated POST endpoint that accepts arbitrary extra properties due to missing whitelist validation in the NestJS pipe. Any unauthenticated attacker can manipulate onboarding configuration, posing a critical risk to any team running their own Hoppscotch instance.
2
CVE-2026-11387CVSS 9.8affects SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
The SMS Alert WooCommerce plugin (all versions through 3.9.5) fails to properly verify a user's identity before processing password reset requests, allowing an unauthenticated attacker to reset any account's password — including administrators — and take full control of the WordPress site.
3
NVIDIA AIStore contains an authentication bypass flaw that, if successfully exploited, can chain into privilege escalation, information disclosure, data tampering, and denial of service — making it a high-value target in any AI/ML infrastructure environment.
4
HTML::Gumbo for Perl (before 0.19) mishandles the HTML template element as a text node, causing strlen() to over-read heap memory, disclosing sensitive heap contents to any caller invoking the default parse() method. Applications processing untrusted HTML with this library are directly exposed.
5
An incorrect privilege assignment vulnerability in the LCweb PrivateContent WordPress plugin (through 9.9.2) allows attackers to escalate privileges, potentially granting unauthorized access to protected content and administrative functions.
6
A use-after-free in Chrome's Skia graphics library (before 150.0.7871.46) can be triggered remotely via a crafted HTML page, potentially enabling a full sandbox escape — making unpatched browser deployments a direct lateral movement risk.
7
A use-after-free in Chrome's Dawn WebGPU backend (before 150.0.7871.46) allows a remote attacker to escape the browser sandbox through a malicious web page, affecting all platforms and requiring no user interaction beyond visiting the page.
8
Another use-after-free in Dawn affects Chrome on macOS specifically (before 150.0.7871.46), enabling remote sandbox escape via crafted HTML — macOS enterprise endpoints running outdated Chrome builds are particularly at risk.
9
A use-after-free in Chrome's ANGLE graphics abstraction layer (before 150.0.7871.46) can be exploited remotely to escape the sandbox, compounding the risk for organizations where Chrome update cycles are delayed by policy or tooling.
10
A second use-after-free in ANGLE within Chrome (before 150.0.7871.46) rounds out a cluster of four browser sandbox escape vulnerabilities published today, reinforcing the urgency of enforcing Chrome 150.0.7871.46 or later across all endpoints.
Today’s recommendation: Prioritize immediate patching of Hoppscotch self-hosted backends and the SMS Alert WordPress plugin, both of which are exploitable without authentication. Enforce Chrome version 150.0.7871.46 or later across all managed endpoints to eliminate the four sandbox escape paths disclosed today.
With multiple unauthenticated critical vulnerabilities and browser-level sandbox escapes published in a single day, now is the right moment to audit your actual attack surface and validate whether any of these affected components are reachable — internally or externally — in your environment.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →