Home / Blog / Recast Blog / July 2026 Third-Party Vulnerabilities and Patches 

July 2026 Third-Party Vulnerabilities and Patches 

Published On Aug 20, 2026 by Tuukka Tiainen Tuukka Tiainen
5 min

July 2026 was the most active month we have recorded so far, passing the previous high set in June. During the month, we identified 1,539 unique vulnerabilities across 108 applications, and vendors released 160 patched versions to fix them. This keeps up the steep upward trend we have seen all through 2026. June had already stood out as an outlier at 1,302 vulnerabilities, and July pushed the number even higher, about 18% more month over month. What changed was the shape of the increase. In June the vulnerability count jumped sharply while the number of affected applications stayed fairly flat. In July the count rose more gently, but the range of affected applications grew a lot, going from 83 to 108, even though the number of released patches stayed almost the same. 

Just like in recent months, most of this activity comes from the large, coordinated security releases that Chromium-based browsers ship. Browser-related products made up roughly 70 percent of all the vulnerabilities we saw during the month, or 1,074 out of 1,539. Google Chrome, Microsoft Edge, and Brave each shipped a single version that fixed somewhere between 330 and 385 vulnerabilities, with Chrome 150 and 151, Edge 150 and 151, and Brave 1.93 being the biggest updates. Because Chromium fixes flow down into the browsers built on top of it, including Microsoft Edge, Brave, Opera, and Vivaldi, one upstream release can spread hundreds of the same fixes across several products and release channels. So these numbers say more about how Chromium coordinates its patching than about hundreds of separate findings. What really sets July apart is how widely the vulnerabilities were spread. Browsers still drove most of the raw count, but this month the activity reached across a much wider part of the catalog, which is why the number of affected applications climbed by roughly 30%. 

Notable vulnerabilities in July third-party patches 

The vulnerabilities below stand out either because a working exploit already exists or because they carry an elevated EPSS score above 0.1. Both of these raise the odds of real-world abuse and shorten the time you have to patch safely, so they are the ones worth prioritizing this month. 

CVE-2026-63077 is a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity, which appears directly in the Application Workspace catalog. The flaw is in the agent polling protocol and lets an attacker run arbitrary code on the server without any authentication, which in practice can mean full control of the build environment. It carries a CVSS score of 9.8, a known exploit already exists, and it has been added to CISA’s Known Exploited Vulnerabilities catalog. The issue affects TeamCity versions before 2026.1.3 and 2025.11.7. Because build servers often hold credentials and can push code straight into production, this one deserves immediate attention. More information is available in the JetBrains security advisory and CISA’s KEV entry. 

Two related vulnerabilities in the Apache HTTP Server reach the catalog through VisualSVN Server, which bundles Apache httpd to serve repositories over HTTP. CVE-2026-23918 is a high severity double free in HTTP/2 request handling that can lead to remote code execution or denial of service. It stands out because it has a public exploit and an elevated EPSS score of about 0.50, one of the highest we saw this month. CVE-2026-49975 is a closely related HTTP/2 issue in the same server that lets a remote attacker trigger a denial of service through memory allocation and compression bomb techniques. It does not yet have a public exploit, but its EPSS score of roughly 0.28 is still high enough to take seriously. Both are a good reminder of how a flaw in a widely reused component can quietly affect a higher-level product that most people would not immediately connect to Apache. Anyone running VisualSVN Server should update to a build that ships the patched Apache version. Further details are available in the Apache HTTP Server advisories and the matching NVD entries: NVD – CVE-2026-23918 and NVD – CVE-2026-49975

CVE-2026-58289 is a critical type confusion vulnerability in Chromium based Microsoft Edge that allows a remote attacker to execute code over the network. Microsoft has confirmed that a known exploit exists. As with any Chromium issue, the same weakness can reach other browsers built on the same engine until each one ships its own update, so the practical advice is to make sure Edge and any related browsers are fully up to date. More information can be found on MSRC

Finally, CVE-2026-11645 makes a return appearance. This is the out of bounds read and write vulnerability in Chrome’s V8 JavaScript engine that we covered last month, and it allows arbitrary code execution through a crafted web page. It is still listed in CISA’s KEV catalog and a working exploit exists. It surfaces again this month because it now shows up through Burp Suite, which embeds a Chromium-based browser for its built-in testing tools. Its EPSS score remains low at about 0.02, but the confirmed real-world exploitation is the reason it still earns a mention. More information on CISA’s KEV article

Browser security updates in July 2026 

Browser updates were once again the biggest driver of vulnerability activity in July, following the same pattern we have seen throughout the year. The table below breaks the counts down by browser. Microsoft Edge led the way with 777 vulnerabilities addressed across six updates, followed by Google Chrome and Brave Browser, which each fixed 435 vulnerabilities over six releases. Vivaldi added another 142 across two updates. Because all four of these browsers are built on Chromium, most of these fixes trace back to the same upstream security releases, so the counts are better read as one coordinated patching effort than as separate findings. Mozilla-based browsers were much quieter by comparison. Mozilla Firefox fixed 62 vulnerabilities across two updates, and its 115 and 140 branches each handled 32 more. Waterfox, which is also built on Firefox, remediated another 32. Put together, these browser numbers make up the large majority of everything disclosed this month, which is why a single busy month for Chromium can move our totals so sharply. 

Browser Vulnerabilities Updates 
Google Chrome 435 
Microsoft Edge 777 
Brave Browser 435 
Mozilla Firefox 62 
Mozilla Firefox 115 32 
Mozilla Firefox 140 32 
Vivaldi 142 
Waterfox 32 

Microsoft product updates included in July 2026 third-party patches 

Microsoft issued security updates for several other products: 

  • Microsoft Edge for Business 
  • Microsoft Edge Beta 
  • Microsoft 365 Apps 
  • Microsoft Visual Studio Code 
  • Microsoft ASP.NET Core Runtime 9.0 
  • Microsoft Visio 
  • Microsoft ASP.NET Core Runtime Hosting Bundle 9.0 
  • Microsoft Visual Studio 2022 Professional 
  • Microsoft Visual Studio 2022 Enterprise 
  • Microsoft .NET Runtime 8.0 
  • Microsoft .NET SDK 9.0 
  • Microsoft ASP.NET Core Runtime 10.0 
  • Microsoft .NET Runtime 9.0 
  • Microsoft ASP.NET Core Runtime 8.0 
  • Microsoft Windows Desktop Runtime 9.0 
  • Microsoft .NET SDK 8.0 
  • Microsoft .NET SDK 10.0 
  • Microsoft Windows Desktop Runtime 8.0 
  • Microsoft Windows Desktop Runtime 10.0 
  • Microsoft .NET Runtime 10.0 
  • Microsoft ASP.NET Core Runtime Hosting Bundle 10.0 
  • Microsoft ASP.NET Core Runtime Hosting Bundle 8.0 

Detailed list of July third-party patches 

Product Name Version Name Vulnerabilities remediated 
Amazon Corretto JDK 25.0.4.7.1 18 
Amazon Corretto JDK 26.0.2.10.1 
Amazon Corretto JDK 11 11.0.32.9.1 11 
Amazon Corretto JDK 17 17.0.20.8.1 
Amazon Corretto JDK 21 21.0.12.8.1 
Amazon Corretto JDK 8 8.502.07.1 10 
Amazon Corretto JRE 8 8.502.07.1 10 
Apache Tomcat 10 10.1.57 
Apache Tomcat 11 11.0.24 
Apache Tomcat 9 9.0.120 
Brave Browser 1.93.129 370 
Brave Browser 1.92.139 27 
Brave Browser 1.92.140 15 
Brave Browser 1.92.143 12 
Brave Browser 1.92.141 
Brave Browser 1.92.144 
Brave Browser 0.0.0 
Brave Origin 1.93.129 370 
Brave Origin 1.92.139 27 
Brave Origin 1.92.140 15 
Brave Origin 1.92.143 12 
Brave Origin 1.92.141 
Brave Origin 1.92.144 
Burp Suite Community Edition 2026.7.1 74 
Burp Suite Community Edition 2026.6 74 
Burp Suite Community Edition 2026.6.0 74 
Burp Suite Professional Edition 2026.7.1 74 
Burp Suite Professional Edition 2026.6 74 
Burp Suite Professional Edition 2026.6.0 74 
Chef Infra Client 18.11.11 
Chef Infra Client for Windows 10 18.11.11 
Chef Infra Client for Windows 11 18.11.11 
Chef Infra Client for Windows Server 2016 18.11.11 
Chef Infra Client for Windows Server 2019 18.11.11 
Chef Infra Client for Windows Server 2022 18.11.11 
Chef Infra Client for Windows Server 2025 18.11.11 
ClamAV 1.5.3 
Erlang OTP 29.0.4.0 
Erlang OTP 28.5.0.4 
Erlang OTP 29.0.3.0 
Erlang OTP 28.5.0.3 
Foxit PDF Editor 2026.1.2.36540 28 
Foxit PDF Editor 13 13.2.5.24109 26 
Foxit PDF Editor 13 13.2.5.63482 
Foxit PDF Editor Pro 13 13.2.5.24109 26 
Foxit PDF Reader 2026.1.2.36540 28 
FreeCAD 1.1.2 
Github CLI 2.97.0 
Github CLI 2.96.0 
GoLand 2026.2 
Google Chrome 150.0.7871.47 382 
Google Chrome 151.0.7922.71 370 
Google Chrome 151.0.7922.72 370 
Google Chrome 150.0.7871.114 27 
Google Chrome 150.0.7871.115 27 
Google Chrome 150.0.7871.125 15 
Google Chrome 150.0.7871.182 12 
Google Chrome 150.0.7871.181 12 
Google Chrome 150.0.7871.128 
Google Chrome 150.0.7871.129 
Google Chrome 150.0.7871.186 
Google Chrome 150.0.7871.187 
Google Chrome for Business 151.0.7922.72 370 
Google Chrome for Business 150.0.7871.115 27 
Google Chrome for Business 150.0.7871.125 15 
Google Chrome for Business 150.0.7871.182 12 
Google Chrome for Business 150.0.7871.129 
Google Chrome for Business 150.0.7871.187 
Google Chrome for Consumers 151.0.7922.72 370 
Google Chrome for Consumers 150.0.7871.115 27 
Google Chrome for Consumers 150.0.7871.125 15 
Google Chrome for Consumers 150.0.7871.182 12 
Google Chrome for Consumers 150.0.7871.129 
Google Chrome for Consumers 150.0.7871.187 
Google Chrome for Education 151.0.7922.72 370 
Google Chrome for Education 150.0.7871.115 27 
Google Chrome for Education 150.0.7871.125 15 
Google Chrome for Education 150.0.7871.182 12 
Google Chrome for Education 150.0.7871.129 
Google Chrome for Education 150.0.7871.187 
Google Go Programming Language 1.25.12 
Google Go Programming Language 1.26.5 
ImageMagick 7.1.2.27 
IntelliJ IDEA 2026.2 
IntelliJ IDEA 2026.1.4 
Liberica JDK 11.0.32.11 18 
Liberica JDK 8.0.502.9 17 
Liberica JDK 25.0.4.9 16 
Liberica JDK 17.0.20.10 16 
Liberica JDK Lite 11.0.32.11 18 
Liberica JDK Lite 8.0.502.9 17 
Liberica JDK Lite 25.0.4.9 16 
Liberica JDK Lite 21.0.12.10 16 
Liberica JRE 11.0.32.11 18 
Liberica JRE 11.0.32.11 17 
Liberica JRE 8.0.502.9 17 
Liberica JRE 21.0.12.10 16 
Liberica JRE 25.0.4.9 16 
Microsoft .NET Runtime 10.0 10.0.10 17 
Microsoft .NET Runtime 8.0 8.0.29.36224 17 
Microsoft .NET Runtime 8.0 8.0.29 17 
Microsoft .NET Runtime 9.0 9.0.18 17 
Microsoft .NET SDK 10.0 10.0.302 17 
Microsoft .NET SDK 8.0 8.0.423 17 
Microsoft .NET SDK 8.0 8.4.2326.32602 17 
Microsoft .NET SDK 9.0 9.0.316 17 
Microsoft 365 Apps 2606 (Build 16.0.20131.20150) 78 
Microsoft 365 Apps 2606 (Build 16.0.20131.20152) 78 
Microsoft ASP.NET Core Runtime 10.0 10.0.10 17 
Microsoft ASP.NET Core Runtime 8.0 8.0.29.26325 17 
Microsoft ASP.NET Core Runtime 8.0 8.0.29 17 
Microsoft ASP.NET Core Runtime 9.0 9.0.18 17 
Microsoft ASP.NET Core Runtime Hosting Bundle 10.0 10.0.10 17 
Microsoft ASP.NET Core Runtime Hosting Bundle 8.0 8.0.29.26325 17 
Microsoft ASP.NET Core Runtime Hosting Bundle 9.0 9.0.18 17 
Microsoft Edge Beta 151.0.4129.59 385 
Microsoft Edge Beta 150.0.4078.48 331 
Microsoft Edge Beta 150.0.4078.48 260 
Microsoft Edge Beta 150.0.4078.65 23 
Microsoft Edge Beta 150.0.4078.65 22 
Microsoft Edge Beta 150.0.4078.50 
Microsoft Edge for Business 151.0.4129.59 385 
Microsoft Edge for Business 150.0.4078.48 331 
Microsoft Edge for Business 150.0.4078.50 301 
Microsoft Edge for Business 150.0.4078.48 260 
Microsoft Edge for Business 150.0.4078.65 23 
Microsoft Edge for Business 150.0.4078.65 22 
Microsoft Edge for Business 150.0.4078.83 19 
Microsoft Edge for Business 150.0.4078.80 14 
Microsoft Edge for Business 150.0.4078.96 12 
Microsoft Edge for Business 150.0.4078.80 
Microsoft Edge for Business 150.0.4078.99 
Microsoft Edge for Business 150.0.4078.83 
Microsoft Edge for Business 150.0.4078.99 
Microsoft Visio 2606 (Build 16.0.20131.20152) 78 
Microsoft Visio 2606 (Build 16.0.20131.20152) 23 
Microsoft Visual Studio 2022 Enterprise 17.14.37502.11 16 
Microsoft Visual Studio 2022 Enterprise 17.12.37502.7 15 
Microsoft Visual Studio 2022 Professional 17.14.37502.11 16 
Microsoft Visual Studio 2022 Professional 17.12.37502.7 15 
Microsoft Visual Studio Code 1.128.1 
Microsoft Windows Desktop Runtime 10.0 10.0.10 17 
Microsoft Windows Desktop Runtime 8.0 8.0.29.36225 17 
Microsoft Windows Desktop Runtime 9.0 9.0.18 17 
MongoDB Community Edition 8.3.7 24 
MongoDB Community Edition 7.0 7.0.39 16 
MongoDB Community Edition 8.0 8.0.28 22 
MongoDB Enterprise Edition 8.3.7 24 
MongoDB Enterprise Edition 7.0 7.0.39 16 
MongoDB Enterprise Edition 8.0 8.0.28 22 
Mozilla Firefox 153.0 60 
Mozilla Firefox 152.0.6 
Mozilla Firefox 152.0.4 
Mozilla Firefox ESR 115 115.38.0 32 
Mozilla Firefox ESR 140 140.13.0 32 
Mozilla Firefox ESR 153 153.0 32 
Mozilla Firefox ESR 153 153.0 31 
Mozilla Thunderbird 153.0 61 
Mozilla Thunderbird 152.0.1 
Mozilla Thunderbird ESR 140 140.13.0 33 
Mozilla Thunderbird ESR 140 140.13.0 32 
Mozilla Thunderbird ESR 140 140.12.1 
Mozilla Thunderbird ESR 153 153.0.1 33 
nginx 1.31.3 
nginx 1.30.4 
Node.js 26.5.1 10 
Node.js 22 LTS 22.23.2 10 
Node.js 24 24.18.1 11 
Notepad++ 8.9.7 
Oracle Java Runtime Environment Version 8 8.0.5010.08 18 
Oracle Java Runtime Environment Version 8 8.0.5010.08 10 
Oracle Java Runtime Environment Version 8 8.0.4910.10 
Oracle Java SE Development Kit 25.0.4.0 10 
Oracle Java SE Development Kit 21 21.0.12.0 10 
Oracle Java SE Development Kit 8 8.0.5010.08 18 
Oracle Java SE Development Kit 8 8.0.5010.08 10 
PaperCut MF 26.0.3.76224 
PaperCut NG 26.0.3.76225 
pgAdmin 4 9.17 10 
PhpStorm 2026.2 
Podman Desktop 1.29.0 12 
Prometheus 3.13.0 
Prometheus 3.13.2 
PyCharm Professional 2026.2 
RabbitMQ Server 4.3.4 
Splunk Enterprise 10.2.5 28 
Splunk Enterprise 10.0.8 28 
Splunk Enterprise 10.4.1 28 
Splunk Enterprise 9.3 9.3.14 
Splunk Enterprise 9.4 9.4.13 28 
Splunk Universal Forwarder 10.2.5 
Splunk Universal Forwarder 10.0.8 
Splunk Universal Forwarder 10.4.1 
Splunk Universal Forwarder 9.4 9.4.13 
TeamCity 2026.1.3 
VisualSVN Server 5.4.8 35 
Vivaldi 8.0.4033.57 127 
Vivaldi 8.1.4087.53 15 
Waterfox 6.6.17 32 
WebStorm 2026.2 
Wireshark 4.6.7 41 
Wireshark 4.4.17 36 
Zulu JDK 17 (LTS) 17.68.17 
Zulu JDK 21 (LTS) 21.52.15 
Zulu JDK 25 (LTS) 25.36.15.0 
Zulu JRE 17 (LTS) 17.68.17 
Zulu JRE 21 (LTS) 21.52.15 
Zulu JRE 25 (LTS) 25.36.15.0 

Share