July 2026 was the most active month we have recorded so far, passing the previous high set in June. During the month, we identified 1,539 unique vulnerabilities across 108 applications, and vendors released 160 patched versions to fix them. This keeps up the steep upward trend we have seen all through 2026. June had already stood out as an outlier at 1,302 vulnerabilities, and July pushed the number even higher, about 18% more month over month. What changed was the shape of the increase. In June the vulnerability count jumped sharply while the number of affected applications stayed fairly flat. In July the count rose more gently, but the range of affected applications grew a lot, going from 83 to 108, even though the number of released patches stayed almost the same.
Just like in recent months, most of this activity comes from the large, coordinated security releases that Chromium-based browsers ship. Browser-related products made up roughly 70 percent of all the vulnerabilities we saw during the month, or 1,074 out of 1,539. Google Chrome, Microsoft Edge, and Brave each shipped a single version that fixed somewhere between 330 and 385 vulnerabilities, with Chrome 150 and 151, Edge 150 and 151, and Brave 1.93 being the biggest updates. Because Chromium fixes flow down into the browsers built on top of it, including Microsoft Edge, Brave, Opera, and Vivaldi, one upstream release can spread hundreds of the same fixes across several products and release channels. So these numbers say more about how Chromium coordinates its patching than about hundreds of separate findings. What really sets July apart is how widely the vulnerabilities were spread. Browsers still drove most of the raw count, but this month the activity reached across a much wider part of the catalog, which is why the number of affected applications climbed by roughly 30%.

Notable vulnerabilities in July third-party patches
The vulnerabilities below stand out either because a working exploit already exists or because they carry an elevated EPSS score above 0.1. Both of these raise the odds of real-world abuse and shorten the time you have to patch safely, so they are the ones worth prioritizing this month.
CVE-2026-63077 is a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity, which appears directly in the Application Workspace catalog. The flaw is in the agent polling protocol and lets an attacker run arbitrary code on the server without any authentication, which in practice can mean full control of the build environment. It carries a CVSS score of 9.8, a known exploit already exists, and it has been added to CISA’s Known Exploited Vulnerabilities catalog. The issue affects TeamCity versions before 2026.1.3 and 2025.11.7. Because build servers often hold credentials and can push code straight into production, this one deserves immediate attention. More information is available in the JetBrains security advisory and CISA’s KEV entry.
Two related vulnerabilities in the Apache HTTP Server reach the catalog through VisualSVN Server, which bundles Apache httpd to serve repositories over HTTP. CVE-2026-23918 is a high severity double free in HTTP/2 request handling that can lead to remote code execution or denial of service. It stands out because it has a public exploit and an elevated EPSS score of about 0.50, one of the highest we saw this month. CVE-2026-49975 is a closely related HTTP/2 issue in the same server that lets a remote attacker trigger a denial of service through memory allocation and compression bomb techniques. It does not yet have a public exploit, but its EPSS score of roughly 0.28 is still high enough to take seriously. Both are a good reminder of how a flaw in a widely reused component can quietly affect a higher-level product that most people would not immediately connect to Apache. Anyone running VisualSVN Server should update to a build that ships the patched Apache version. Further details are available in the Apache HTTP Server advisories and the matching NVD entries: NVD – CVE-2026-23918 and NVD – CVE-2026-49975.
CVE-2026-58289 is a critical type confusion vulnerability in Chromium based Microsoft Edge that allows a remote attacker to execute code over the network. Microsoft has confirmed that a known exploit exists. As with any Chromium issue, the same weakness can reach other browsers built on the same engine until each one ships its own update, so the practical advice is to make sure Edge and any related browsers are fully up to date. More information can be found on MSRC.
Finally, CVE-2026-11645 makes a return appearance. This is the out of bounds read and write vulnerability in Chrome’s V8 JavaScript engine that we covered last month, and it allows arbitrary code execution through a crafted web page. It is still listed in CISA’s KEV catalog and a working exploit exists. It surfaces again this month because it now shows up through Burp Suite, which embeds a Chromium-based browser for its built-in testing tools. Its EPSS score remains low at about 0.02, but the confirmed real-world exploitation is the reason it still earns a mention. More information on CISA’s KEV article.

Browser security updates in July 2026
Browser updates were once again the biggest driver of vulnerability activity in July, following the same pattern we have seen throughout the year. The table below breaks the counts down by browser. Microsoft Edge led the way with 777 vulnerabilities addressed across six updates, followed by Google Chrome and Brave Browser, which each fixed 435 vulnerabilities over six releases. Vivaldi added another 142 across two updates. Because all four of these browsers are built on Chromium, most of these fixes trace back to the same upstream security releases, so the counts are better read as one coordinated patching effort than as separate findings. Mozilla-based browsers were much quieter by comparison. Mozilla Firefox fixed 62 vulnerabilities across two updates, and its 115 and 140 branches each handled 32 more. Waterfox, which is also built on Firefox, remediated another 32. Put together, these browser numbers make up the large majority of everything disclosed this month, which is why a single busy month for Chromium can move our totals so sharply.
| Browser | Vulnerabilities | Updates |
| Google Chrome | 435 | 6 |
| Microsoft Edge | 777 | 6 |
| Brave Browser | 435 | 6 |
| Mozilla Firefox | 62 | 2 |
| Mozilla Firefox 115 | 32 | 1 |
| Mozilla Firefox 140 | 32 | 1 |
| Vivaldi | 142 | 2 |
| Waterfox | 32 | 1 |
Microsoft product updates included in July 2026 third-party patches
Microsoft issued security updates for several other products:
- Microsoft Edge for Business
- Microsoft Edge Beta
- Microsoft 365 Apps
- Microsoft Visual Studio Code
- Microsoft ASP.NET Core Runtime 9.0
- Microsoft Visio
- Microsoft ASP.NET Core Runtime Hosting Bundle 9.0
- Microsoft Visual Studio 2022 Professional
- Microsoft Visual Studio 2022 Enterprise
- Microsoft .NET Runtime 8.0
- Microsoft .NET SDK 9.0
- Microsoft ASP.NET Core Runtime 10.0
- Microsoft .NET Runtime 9.0
- Microsoft ASP.NET Core Runtime 8.0
- Microsoft Windows Desktop Runtime 9.0
- Microsoft .NET SDK 8.0
- Microsoft .NET SDK 10.0
- Microsoft Windows Desktop Runtime 8.0
- Microsoft Windows Desktop Runtime 10.0
- Microsoft .NET Runtime 10.0
- Microsoft ASP.NET Core Runtime Hosting Bundle 10.0
- Microsoft ASP.NET Core Runtime Hosting Bundle 8.0
Detailed list of July third-party patches
| Product Name | Version Name | Vulnerabilities remediated |
| Amazon Corretto JDK | 25.0.4.7.1 | 18 |
| Amazon Corretto JDK | 26.0.2.10.1 | 9 |
| Amazon Corretto JDK 11 | 11.0.32.9.1 | 11 |
| Amazon Corretto JDK 17 | 17.0.20.8.1 | 9 |
| Amazon Corretto JDK 21 | 21.0.12.8.1 | 9 |
| Amazon Corretto JDK 8 | 8.502.07.1 | 10 |
| Amazon Corretto JRE 8 | 8.502.07.1 | 10 |
| Apache Tomcat 10 | 10.1.57 | 2 |
| Apache Tomcat 11 | 11.0.24 | 2 |
| Apache Tomcat 9 | 9.0.120 | 2 |
| Brave Browser | 1.93.129 | 370 |
| Brave Browser | 1.92.139 | 27 |
| Brave Browser | 1.92.140 | 15 |
| Brave Browser | 1.92.143 | 12 |
| Brave Browser | 1.92.141 | 7 |
| Brave Browser | 1.92.144 | 4 |
| Brave Browser | 0.0.0 | 4 |
| Brave Origin | 1.93.129 | 370 |
| Brave Origin | 1.92.139 | 27 |
| Brave Origin | 1.92.140 | 15 |
| Brave Origin | 1.92.143 | 12 |
| Brave Origin | 1.92.141 | 7 |
| Brave Origin | 1.92.144 | 4 |
| Burp Suite Community Edition | 2026.7.1 | 74 |
| Burp Suite Community Edition | 2026.6 | 74 |
| Burp Suite Community Edition | 2026.6.0 | 74 |
| Burp Suite Professional Edition | 2026.7.1 | 74 |
| Burp Suite Professional Edition | 2026.6 | 74 |
| Burp Suite Professional Edition | 2026.6.0 | 74 |
| Chef Infra Client | 18.11.11 | 3 |
| Chef Infra Client for Windows 10 | 18.11.11 | 3 |
| Chef Infra Client for Windows 11 | 18.11.11 | 3 |
| Chef Infra Client for Windows Server 2016 | 18.11.11 | 3 |
| Chef Infra Client for Windows Server 2019 | 18.11.11 | 3 |
| Chef Infra Client for Windows Server 2022 | 18.11.11 | 3 |
| Chef Infra Client for Windows Server 2025 | 18.11.11 | 3 |
| ClamAV | 1.5.3 | 8 |
| Erlang OTP | 29.0.4.0 | 8 |
| Erlang OTP | 28.5.0.4 | 8 |
| Erlang OTP | 29.0.3.0 | 5 |
| Erlang OTP | 28.5.0.3 | 5 |
| Foxit PDF Editor | 2026.1.2.36540 | 28 |
| Foxit PDF Editor 13 | 13.2.5.24109 | 26 |
| Foxit PDF Editor 13 | 13.2.5.63482 | 6 |
| Foxit PDF Editor Pro 13 | 13.2.5.24109 | 26 |
| Foxit PDF Reader | 2026.1.2.36540 | 28 |
| FreeCAD | 1.1.2 | 1 |
| Github CLI | 2.97.0 | 4 |
| Github CLI | 2.96.0 | 1 |
| GoLand | 2026.2 | 3 |
| Google Chrome | 150.0.7871.47 | 382 |
| Google Chrome | 151.0.7922.71 | 370 |
| Google Chrome | 151.0.7922.72 | 370 |
| Google Chrome | 150.0.7871.114 | 27 |
| Google Chrome | 150.0.7871.115 | 27 |
| Google Chrome | 150.0.7871.125 | 15 |
| Google Chrome | 150.0.7871.182 | 12 |
| Google Chrome | 150.0.7871.181 | 12 |
| Google Chrome | 150.0.7871.128 | 7 |
| Google Chrome | 150.0.7871.129 | 7 |
| Google Chrome | 150.0.7871.186 | 4 |
| Google Chrome | 150.0.7871.187 | 4 |
| Google Chrome for Business | 151.0.7922.72 | 370 |
| Google Chrome for Business | 150.0.7871.115 | 27 |
| Google Chrome for Business | 150.0.7871.125 | 15 |
| Google Chrome for Business | 150.0.7871.182 | 12 |
| Google Chrome for Business | 150.0.7871.129 | 7 |
| Google Chrome for Business | 150.0.7871.187 | 4 |
| Google Chrome for Consumers | 151.0.7922.72 | 370 |
| Google Chrome for Consumers | 150.0.7871.115 | 27 |
| Google Chrome for Consumers | 150.0.7871.125 | 15 |
| Google Chrome for Consumers | 150.0.7871.182 | 12 |
| Google Chrome for Consumers | 150.0.7871.129 | 7 |
| Google Chrome for Consumers | 150.0.7871.187 | 4 |
| Google Chrome for Education | 151.0.7922.72 | 370 |
| Google Chrome for Education | 150.0.7871.115 | 27 |
| Google Chrome for Education | 150.0.7871.125 | 15 |
| Google Chrome for Education | 150.0.7871.182 | 12 |
| Google Chrome for Education | 150.0.7871.129 | 7 |
| Google Chrome for Education | 150.0.7871.187 | 4 |
| Google Go Programming Language | 1.25.12 | 2 |
| Google Go Programming Language | 1.26.5 | 2 |
| ImageMagick | 7.1.2.27 | 3 |
| IntelliJ IDEA | 2026.2 | 1 |
| IntelliJ IDEA | 2026.1.4 | 1 |
| Liberica JDK | 11.0.32.11 | 18 |
| Liberica JDK | 8.0.502.9 | 17 |
| Liberica JDK | 25.0.4.9 | 16 |
| Liberica JDK | 17.0.20.10 | 16 |
| Liberica JDK Lite | 11.0.32.11 | 18 |
| Liberica JDK Lite | 8.0.502.9 | 17 |
| Liberica JDK Lite | 25.0.4.9 | 16 |
| Liberica JDK Lite | 21.0.12.10 | 16 |
| Liberica JRE | 11.0.32.11 | 18 |
| Liberica JRE | 11.0.32.11 | 17 |
| Liberica JRE | 8.0.502.9 | 17 |
| Liberica JRE | 21.0.12.10 | 16 |
| Liberica JRE | 25.0.4.9 | 16 |
| Microsoft .NET Runtime 10.0 | 10.0.10 | 17 |
| Microsoft .NET Runtime 8.0 | 8.0.29.36224 | 17 |
| Microsoft .NET Runtime 8.0 | 8.0.29 | 17 |
| Microsoft .NET Runtime 9.0 | 9.0.18 | 17 |
| Microsoft .NET SDK 10.0 | 10.0.302 | 17 |
| Microsoft .NET SDK 8.0 | 8.0.423 | 17 |
| Microsoft .NET SDK 8.0 | 8.4.2326.32602 | 17 |
| Microsoft .NET SDK 9.0 | 9.0.316 | 17 |
| Microsoft 365 Apps | 2606 (Build 16.0.20131.20150) | 78 |
| Microsoft 365 Apps | 2606 (Build 16.0.20131.20152) | 78 |
| Microsoft ASP.NET Core Runtime 10.0 | 10.0.10 | 17 |
| Microsoft ASP.NET Core Runtime 8.0 | 8.0.29.26325 | 17 |
| Microsoft ASP.NET Core Runtime 8.0 | 8.0.29 | 17 |
| Microsoft ASP.NET Core Runtime 9.0 | 9.0.18 | 17 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 10.0 | 10.0.10 | 17 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 8.0 | 8.0.29.26325 | 17 |
| Microsoft ASP.NET Core Runtime Hosting Bundle 9.0 | 9.0.18 | 17 |
| Microsoft Edge Beta | 151.0.4129.59 | 385 |
| Microsoft Edge Beta | 150.0.4078.48 | 331 |
| Microsoft Edge Beta | 150.0.4078.48 | 260 |
| Microsoft Edge Beta | 150.0.4078.65 | 23 |
| Microsoft Edge Beta | 150.0.4078.65 | 22 |
| Microsoft Edge Beta | 150.0.4078.50 | 1 |
| Microsoft Edge for Business | 151.0.4129.59 | 385 |
| Microsoft Edge for Business | 150.0.4078.48 | 331 |
| Microsoft Edge for Business | 150.0.4078.50 | 301 |
| Microsoft Edge for Business | 150.0.4078.48 | 260 |
| Microsoft Edge for Business | 150.0.4078.65 | 23 |
| Microsoft Edge for Business | 150.0.4078.65 | 22 |
| Microsoft Edge for Business | 150.0.4078.83 | 19 |
| Microsoft Edge for Business | 150.0.4078.80 | 14 |
| Microsoft Edge for Business | 150.0.4078.96 | 12 |
| Microsoft Edge for Business | 150.0.4078.80 | 9 |
| Microsoft Edge for Business | 150.0.4078.99 | 7 |
| Microsoft Edge for Business | 150.0.4078.83 | 7 |
| Microsoft Edge for Business | 150.0.4078.99 | 5 |
| Microsoft Visio | 2606 (Build 16.0.20131.20152) | 78 |
| Microsoft Visio | 2606 (Build 16.0.20131.20152) | 23 |
| Microsoft Visual Studio 2022 Enterprise | 17.14.37502.11 | 16 |
| Microsoft Visual Studio 2022 Enterprise | 17.12.37502.7 | 15 |
| Microsoft Visual Studio 2022 Professional | 17.14.37502.11 | 16 |
| Microsoft Visual Studio 2022 Professional | 17.12.37502.7 | 15 |
| Microsoft Visual Studio Code | 1.128.1 | 6 |
| Microsoft Windows Desktop Runtime 10.0 | 10.0.10 | 17 |
| Microsoft Windows Desktop Runtime 8.0 | 8.0.29.36225 | 17 |
| Microsoft Windows Desktop Runtime 9.0 | 9.0.18 | 17 |
| MongoDB Community Edition | 8.3.7 | 24 |
| MongoDB Community Edition 7.0 | 7.0.39 | 16 |
| MongoDB Community Edition 8.0 | 8.0.28 | 22 |
| MongoDB Enterprise Edition | 8.3.7 | 24 |
| MongoDB Enterprise Edition 7.0 | 7.0.39 | 16 |
| MongoDB Enterprise Edition 8.0 | 8.0.28 | 22 |
| Mozilla Firefox | 153.0 | 60 |
| Mozilla Firefox | 152.0.6 | 2 |
| Mozilla Firefox | 152.0.4 | 1 |
| Mozilla Firefox ESR 115 | 115.38.0 | 32 |
| Mozilla Firefox ESR 140 | 140.13.0 | 32 |
| Mozilla Firefox ESR 153 | 153.0 | 32 |
| Mozilla Firefox ESR 153 | 153.0 | 31 |
| Mozilla Thunderbird | 153.0 | 61 |
| Mozilla Thunderbird | 152.0.1 | 2 |
| Mozilla Thunderbird ESR 140 | 140.13.0 | 33 |
| Mozilla Thunderbird ESR 140 | 140.13.0 | 32 |
| Mozilla Thunderbird ESR 140 | 140.12.1 | 2 |
| Mozilla Thunderbird ESR 153 | 153.0.1 | 33 |
| nginx | 1.31.3 | 3 |
| nginx | 1.30.4 | 3 |
| Node.js | 26.5.1 | 10 |
| Node.js 22 LTS | 22.23.2 | 10 |
| Node.js 24 | 24.18.1 | 11 |
| Notepad++ | 8.9.7 | 4 |
| Oracle Java Runtime Environment Version 8 | 8.0.5010.08 | 18 |
| Oracle Java Runtime Environment Version 8 | 8.0.5010.08 | 10 |
| Oracle Java Runtime Environment Version 8 | 8.0.4910.10 | 7 |
| Oracle Java SE Development Kit | 25.0.4.0 | 10 |
| Oracle Java SE Development Kit 21 | 21.0.12.0 | 10 |
| Oracle Java SE Development Kit 8 | 8.0.5010.08 | 18 |
| Oracle Java SE Development Kit 8 | 8.0.5010.08 | 10 |
| PaperCut MF | 26.0.3.76224 | 2 |
| PaperCut NG | 26.0.3.76225 | 2 |
| pgAdmin 4 | 9.17 | 10 |
| PhpStorm | 2026.2 | 2 |
| Podman Desktop | 1.29.0 | 12 |
| Prometheus | 3.13.0 | 3 |
| Prometheus | 3.13.2 | 1 |
| PyCharm Professional | 2026.2 | 1 |
| RabbitMQ Server | 4.3.4 | 2 |
| Splunk Enterprise | 10.2.5 | 28 |
| Splunk Enterprise | 10.0.8 | 28 |
| Splunk Enterprise | 10.4.1 | 28 |
| Splunk Enterprise 9.3 | 9.3.14 | 1 |
| Splunk Enterprise 9.4 | 9.4.13 | 28 |
| Splunk Universal Forwarder | 10.2.5 | 3 |
| Splunk Universal Forwarder | 10.0.8 | 3 |
| Splunk Universal Forwarder | 10.4.1 | 3 |
| Splunk Universal Forwarder 9.4 | 9.4.13 | 3 |
| TeamCity | 2026.1.3 | 1 |
| VisualSVN Server | 5.4.8 | 35 |
| Vivaldi | 8.0.4033.57 | 127 |
| Vivaldi | 8.1.4087.53 | 15 |
| Waterfox | 6.6.17 | 32 |
| WebStorm | 2026.2 | 4 |
| Wireshark | 4.6.7 | 41 |
| Wireshark | 4.4.17 | 36 |
| Zulu JDK 17 (LTS) | 17.68.17 | 9 |
| Zulu JDK 21 (LTS) | 21.52.15 | 9 |
| Zulu JDK 25 (LTS) | 25.36.15.0 | 9 |
| Zulu JRE 17 (LTS) | 17.68.17 | 9 |
| Zulu JRE 21 (LTS) | 21.52.15 | 9 |
| Zulu JRE 25 (LTS) | 25.36.15.0 | 9 |