Daily briefing · July 1, 2026

368 New CVEs on July 1: Perfect-10 Hoppscotch Flaw, WordPress Admin Takeover, and Four Chrome Sandbox Escapes Dominate

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

July 1, 2026 brought 368 new vulnerabilities, 54 of them critical — with no active exploitation confirmed yet, but several entries carry maximum-severity scores and high exploitation potential. A perfect CVSS 10.0 mass assignment flaw in Hoppscotch self-hosted deployments leads the day, flanked by two unauthenticated privilege escalation bugs in widely deployed WordPress and AI infrastructure, and a cluster of four use-after-free sandbox escape vulnerabilities in Google Chrome.

Today’s brief
  • Hoppscotch scores CVSS 10.0: an unauthenticated endpoint in self-hosted backends allows mass assignment, no credentials required.
  • WordPress SMS Alert plugin (≤3.9.5) enables full admin account takeover via password reset without identity verification.
  • NVIDIA AIStore authentication bypass can lead to privilege escalation, data tampering, and denial of service.
  • Four use-after-free bugs in Chrome (Skia, Dawn, ANGLE) allow remote sandbox escape via a crafted web page — update immediately.
54
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-50160CVSS 10affects hoppscotch
A CVSS 10.0 mass assignment vulnerability in Hoppscotch self-hosted backends (≤2026.4.1) exposes an unauthenticated POST endpoint that accepts arbitrary extra properties due to missing whitelist validation in the NestJS pipe. Any unauthenticated attacker can manipulate onboarding configuration, posing a critical risk to any team running their own Hoppscotch instance.
2
CVE-2026-11387CVSS 9.8affects SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
The SMS Alert WooCommerce plugin (all versions through 3.9.5) fails to properly verify a user's identity before processing password reset requests, allowing an unauthenticated attacker to reset any account's password — including administrators — and take full control of the WordPress site.
3
CVE-2026-24270CVSS 9.8affects AIStore framework
NVIDIA AIStore contains an authentication bypass flaw that, if successfully exploited, can chain into privilege escalation, information disclosure, data tampering, and denial of service — making it a high-value target in any AI/ML infrastructure environment.
4
CVE-2025-15646CVSS 9.8affects HTML::Gumbo
HTML::Gumbo for Perl (before 0.19) mishandles the HTML template element as a text node, causing strlen() to over-read heap memory, disclosing sensitive heap contents to any caller invoking the default parse() method. Applications processing untrusted HTML with this library are directly exposed.
5
CVE-2026-57692CVSS 9.8affects PrivateContent
An incorrect privilege assignment vulnerability in the LCweb PrivateContent WordPress plugin (through 9.9.2) allows attackers to escalate privileges, potentially granting unauthorized access to protected content and administrative functions.
6
CVE-2026-14419CVSS 9.6affects Chrome
A use-after-free in Chrome's Skia graphics library (before 150.0.7871.46) can be triggered remotely via a crafted HTML page, potentially enabling a full sandbox escape — making unpatched browser deployments a direct lateral movement risk.
7
CVE-2026-14417CVSS 9.6affects Chrome
A use-after-free in Chrome's Dawn WebGPU backend (before 150.0.7871.46) allows a remote attacker to escape the browser sandbox through a malicious web page, affecting all platforms and requiring no user interaction beyond visiting the page.
8
CVE-2026-14424CVSS 9.6affects Chrome
Another use-after-free in Dawn affects Chrome on macOS specifically (before 150.0.7871.46), enabling remote sandbox escape via crafted HTML — macOS enterprise endpoints running outdated Chrome builds are particularly at risk.
9
CVE-2026-14425CVSS 9.6affects Chrome
A use-after-free in Chrome's ANGLE graphics abstraction layer (before 150.0.7871.46) can be exploited remotely to escape the sandbox, compounding the risk for organizations where Chrome update cycles are delayed by policy or tooling.
10
CVE-2026-14390CVSS 9.6affects Chrome
A second use-after-free in ANGLE within Chrome (before 150.0.7871.46) rounds out a cluster of four browser sandbox escape vulnerabilities published today, reinforcing the urgency of enforcing Chrome 150.0.7871.46 or later across all endpoints.
Today’s recommendation: Prioritize immediate patching of Hoppscotch self-hosted backends and the SMS Alert WordPress plugin, both of which are exploitable without authentication. Enforce Chrome version 150.0.7871.46 or later across all managed endpoints to eliminate the four sandbox escape paths disclosed today.
With multiple unauthenticated critical vulnerabilities and browser-level sandbox escapes published in a single day, now is the right moment to audit your actual attack surface and validate whether any of these affected components are reachable — internally or externally — in your environment.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share