Daily briefing · July 1, 2026

368 New CVEs on July 1: Perfect-10 Hoppscotch Flaw, WordPress Admin Takeover, and Four Chrome Sandbox Escapes Dominate

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

July 1, 2026 brought 368 new vulnerabilities, 54 of them critical — with no active exploitation confirmed yet, but several entries carry maximum-severity scores and high exploitation potential. A perfect CVSS 10.0 mass assignment flaw in Hoppscotch self-hosted deployments leads the day, flanked by two unauthenticated privilege escalation bugs in widely deployed WordPress and AI infrastructure, and a cluster of four use-after-free sandbox escape vulnerabilities in Google Chrome.

Today’s brief
  • Hoppscotch scores CVSS 10.0: an unauthenticated endpoint in self-hosted backends allows mass assignment, no credentials required.
  • WordPress SMS Alert plugin (≤3.9.5) enables full admin account takeover via password reset without identity verification.
  • NVIDIA AIStore authentication bypass can lead to privilege escalation, data tampering, and denial of service.
  • Four use-after-free bugs in Chrome (Skia, Dawn, ANGLE) allow remote sandbox escape via a crafted web page — update immediately.
54
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-50160CVSS 10affects hoppscotch
A CVSS 10.0 mass assignment vulnerability in Hoppscotch self-hosted backends (≤2026.4.1) exposes an unauthenticated POST endpoint that accepts arbitrary extra properties due to missing whitelist validation in the NestJS pipe. Any unauthenticated attacker can manipulate onboarding configuration, posing a critical risk to any team running their own Hoppscotch instance.
2
CVE-2026-11387CVSS 9.8affects SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
The SMS Alert WooCommerce plugin (all versions through 3.9.5) fails to properly verify a user's identity before processing password reset requests, allowing an unauthenticated attacker to reset any account's password — including administrators — and take full control of the WordPress site.
3
CVE-2026-24270CVSS 9.8affects AIStore framework
NVIDIA AIStore contains an authentication bypass flaw that, if successfully exploited, can chain into privilege escalation, information disclosure, data tampering, and denial of service — making it a high-value target in any AI/ML infrastructure environment.
4
CVE-2025-15646CVSS 9.8affects HTML::Gumbo
HTML::Gumbo for Perl (before 0.19) mishandles the HTML template element as a text node, causing strlen() to over-read heap memory, disclosing sensitive heap contents to any caller invoking the default parse() method. Applications processing untrusted HTML with this library are directly exposed.
5
CVE-2026-57692CVSS 9.8affects PrivateContent
An incorrect privilege assignment vulnerability in the LCweb PrivateContent WordPress plugin (through 9.9.2) allows attackers to escalate privileges, potentially granting unauthorized access to protected content and administrative functions.
6
CVE-2026-14419CVSS 9.6affects Chrome
A use-after-free in Chrome's Skia graphics library (before 150.0.7871.46) can be triggered remotely via a crafted HTML page, potentially enabling a full sandbox escape — making unpatched browser deployments a direct lateral movement risk.
7
CVE-2026-14417CVSS 9.6affects Chrome
A use-after-free in Chrome's Dawn WebGPU backend (before 150.0.7871.46) allows a remote attacker to escape the browser sandbox through a malicious web page, affecting all platforms and requiring no user interaction beyond visiting the page.
8
CVE-2026-14424CVSS 9.6affects Chrome
Another use-after-free in Dawn affects Chrome on macOS specifically (before 150.0.7871.46), enabling remote sandbox escape via crafted HTML — macOS enterprise endpoints running outdated Chrome builds are particularly at risk.
9
CVE-2026-14425CVSS 9.6affects Chrome
A use-after-free in Chrome's ANGLE graphics abstraction layer (before 150.0.7871.46) can be exploited remotely to escape the sandbox, compounding the risk for organizations where Chrome update cycles are delayed by policy or tooling.
10
CVE-2026-14390CVSS 9.6affects Chrome
A second use-after-free in ANGLE within Chrome (before 150.0.7871.46) rounds out a cluster of four browser sandbox escape vulnerabilities published today, reinforcing the urgency of enforcing Chrome 150.0.7871.46 or later across all endpoints.
Today’s recommendation: Prioritize immediate patching of Hoppscotch self-hosted backends and the SMS Alert WordPress plugin, both of which are exploitable without authentication. Enforce Chrome version 150.0.7871.46 or later across all managed endpoints to eliminate the four sandbox escape paths disclosed today.
With multiple unauthenticated critical vulnerabilities and browser-level sandbox escapes published in a single day, now is the right moment to audit your actual attack surface and validate whether any of these affected components are reachable — internally or externally — in your environment.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share