
miniOrange Social Login CVE-2026-12761: Patch WordPress Auth Bypass
NVD published critical CVE-2026-12761 for the miniOrange Social Login WordPress plugin. Update to the current version and review privileged accounts.

NVD published critical CVE-2026-12761 for the miniOrange Social Login WordPress plugin. Update to the current version and review privileged accounts.

NVD added high and critical admin-tool CVEs for HestiaCP and mcp-server-kubernetes. Hosting and Kubernetes admins should update, review access, and watch the ShareFile incident.

CISA added CVE-2026-56291 for Balbooa Forms and CVE-2026-48939 for iCagenda to KEV. Joomla site owners should patch, disable, or remove affected extensions by July 13, 2026.

NVD published a July 10 high and critical CVE window affecting PraisonAI, Crawl4AI, Vikunja, Capgo, Lucee CFML Server, and FlaskBB. Patch, restrict exposure, and review self-hosted AI and dev tools.

Palo Alto’s July 2026 PAN-OS advisory set includes CVE-2026-0288, LSVPN auth bypass, management-interface SSRF, CLI command injection, and IPv6 policy-bypass fixes.

TYPO3 published a High severity Form Framework access-control fix for CVE-2026-11607. Back up, update, restrict form-editing rights, and verify forms.

cPanel EasyApache 4 25.70 updates PHP and ea-libcurl for CVE fixes, while Sitejet Builder 4.11.0-1 tightens read-only API token behavior.

Drupal.org published July 8 contributed-project advisories including critical unsupported modules and a Location Selector SQL injection fix.

Ubuntu USN-8516-1 and USN-8517-1 patch Apache HTTP Server and ClamAV vulnerabilities. Update hosting, mail, and scanning servers.

WHMCS 9.0.6 and 8.13.5 include security and stability updates. Back up files and database, update, and verify billing workflows.