Security Digest: July 8, 2026 - 30 Critical Vulnerabilities
Today’s list is dominated by remote code execution, authentication bypass, privilege escalation, arbitrary file access, and cross-tenant exposure across WordPress plugins, Goploy, Coder, Plesk, and enterprise platforms. The most urgent risks are the Goploy authorization flaws, the Plesk XML-RPC cross-tenant credential disclosure, and multiple WordPress plugin bugs that let unauthenticated attackers take over sites or delete files.
· 17 min read
July 8, 2026: 30 Critical Vulnerabilities Demand Immediate Action
Executive Summary
Today’s list is dominated by remote code execution, authentication bypass, privilege escalation, arbitrary file access, and cross-tenant exposure across WordPress plugins, Goploy, Coder, Plesk, and enterprise platforms. The most urgent risks are the Goploy authorization flaws, the Plesk XML-RPC cross-tenant credential disclosure, and multiple WordPress plugin bugs that let unauthenticated attackers take over sites or delete files.
Action now: patch exposed systems first, disable vulnerable plugins and features where possible, and assume compromise if any of these products are internet-facing and unpatched.
Critical Vulnerabilities
- CVE-2026-56843: Plesk XML-RPC authorization bypass and cross-tenant RCE
- Impact: Low-privileged customers can view other tenants’ domains and FTP credentials, then use them to execute code as another tenant.
- Affected Systems: WebPros Plesk before 18.0.78.4.
- Immediate Action: Upgrade immediately; review customer account access and rotate exposed FTP credentials.
- Mitigation: Apply the vendor fix and restrict XML-RPC access until patched.
- CVE-2026-12153: WP Learn Manager plugin auth bypass
- Impact: Unauthenticated attackers can install and activate arbitrary WordPress.org plugins.
- Affected Systems: WP Learn Manager up to 1.1.8.
- Immediate Action: Disable the plugin now if you cannot patch immediately.
- Mitigation: Update to a fixed release; audit installed plugins for unexpected additions.
- CVE-2026-9701: Eventer password reset key exposure
- Impact: Attackers can reset passwords and take over accounts, including admins when paired with SQL injection.
- Affected Systems: Eventer up to 4.4.2; password reset flow only works on PHP 7.4 and earlier.
- Immediate Action: Patch or disable the plugin; rotate admin credentials if exposed.
- Mitigation: Update Eventer and remove PHP 7.4 where possible.
- CVE-2026-9695: DELMIA Apriso improper authentication
- Impact: Privileged server access may be obtained by an attacker.
- Affected Systems: DELMIA Apriso Release 2020 through Release 2026.
- Immediate Action: Restrict access to trusted networks and apply vendor guidance urgently.
- Mitigation: Patch to a fixed release and review authentication logs.
- CVE-2026-53552: Goploy namespace escape to file tampering and RCE
- Impact: Managers can read, overwrite, delete, and redirect projects in other namespaces; URL changes can lead to RCE on deploy.
- Affected Systems: zhenorzz/goploy develop HEAD and 1.17.5.
- Immediate Action: Treat any exposed Goploy instance as high risk; limit manager roles and patch immediately.
- Mitigation: Upgrade to a fixed build; verify namespace-scoped authorization on all project/file endpoints.
- CVE-2026-14487: Simple Coherent Form arbitrary file deletion
- Impact: Unauthenticated attackers can delete arbitrary files, including
wp-config.php, enabling takeover. - Affected Systems: Simple Coherent Form up to 2.4.13.
- Immediate Action: Disable the plugin and inspect for deleted core files.
- Mitigation: Update immediately; rotate secrets if any sensitive file may have been removed.
- Impact: Unauthenticated attackers can delete arbitrary files, including
- CVE-2026-14489: WHMCS Bridge arbitrary file upload
- Impact: Authenticated Custom-level users can upload arbitrary files, potentially leading to RCE.
- Affected Systems: WHMCS Bridge up to 6.9.
- Immediate Action: Remove upload access for non-admins and patch.
- Mitigation: Upgrade and review the web root for unexpected files.
- CVE-2026-14158: Widget Logic Visual RCE
- Impact: Subscriber-level attackers can execute code through a malicious widget rule.
- Affected Systems: Widget Logic Visual up to 1.52.
- Immediate Action: Disable the plugin on public sites now.
- Mitigation: Update and audit widget settings for injected code.
- CVE-2026-14482: 多说社会化评论框 privilege escalation
- Impact: Unauthenticated attackers can change WordPress options and create admin accounts.
- Affected Systems: Version 1.2 and earlier.
- Immediate Action: Remove the plugin immediately.
- Mitigation: Patch, then review
default_roleand registration settings.
- CVE-2026-14495: DoLogin Security authentication bypass
- Impact: Attackers can brute-force passwordless login tokens and impersonate users, including admins.
- Affected Systems: DoLogin Security up to 4.3.
- Immediate Action: Disable passwordless login links and patch.
- Mitigation: Upgrade and invalidate active magic links.
- CVE-2026-55429: Coder cross-workspace app reassignment
- Impact: Elevated provisioners/template authors can reassign apps across workspaces, affecting build integrity.
- Affected Systems: Coder before 2.29.7, 2.32.7, 2.33.8, 2.34.2.
- Immediate Action: Upgrade Coder and review provisioner permissions.
- Mitigation: Apply the fixed release and validate workspace ownership checks.
- CVE-2026-55427: Coder SSH config injection
- Impact: Malicious server-supplied SSH settings can alter user SSH behavior.
- Affected Systems: Coder before 2.29.7, 2.32.7, 2.33.8, 2.34.2.
- Immediate Action: Inspect generated
~/.ssh/configentries and patch. - Mitigation: Upgrade and use
--dry-runbefore applying config changes.
- CVE-2026-57251: PDF crash via out-of-bounds access
- Impact: Opening a crafted PDF can crash the application.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Block suspicious PDFs from untrusted sources.
- Mitigation: Apply the vendor update and harden file intake.
- CVE-2026-57250: PDF JavaScript form reset crash
- Impact: Crafted PDF JavaScript can crash the app.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Disable JavaScript in PDF workflows where possible.
- Mitigation: Patch the viewer and restrict untrusted documents.
- CVE-2026-57252: PDF attachment panel crash
- Impact: Malicious PDF actions can crash the application.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Treat external PDFs as hostile.
- Mitigation: Update the application and sandbox document rendering.
- CVE-2026-57256: PDF list box invalid pointer crash
- Impact: A crafted PDF can trigger a crash through invalid object handling.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Patch and isolate PDF processing.
- Mitigation: Restrict JavaScript and deploy the vendor fix.
- CVE-2026-13126: PDF popup annotation crash
- Impact: Crafted PDFs can crash the app after page deletion.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Block untrusted PDF attachments at the gateway.
- Mitigation: Apply updates and monitor for repeated viewer crashes.
- CVE-2026-13127: PDF thumbnail invalid page object crash
- Impact: Malicious PDF rewrite actions can crash the app.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Patch the viewer and disable active content.
- Mitigation: Use a hardened PDF renderer.
- CVE-2026-13128: PDF document view crash
- Impact: Crafted scripts can crash the application.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Quarantine suspicious PDFs.
- Mitigation: Update and sandbox document handling.
- CVE-2026-13129: PDF field tree invalid pointer read
- Impact: A malformed PDF can crash the application.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Limit PDF processing to trusted sources.
- Mitigation: Deploy the vendor patch.
- CVE-2026-57237: PDF form field property crash
- Impact: Crafted field changes can crash the application.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Patch and monitor document viewers.
- Mitigation: Update the application and disable scripting where feasible.
- CVE-2026-57238: PDF deleted form object crash
- Impact: Accessing deleted form objects can crash the app.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Treat crash spikes as suspicious.
- Mitigation: Apply the update and isolate rendering.
- CVE-2026-57240: PDF stale field pointer crash
- Impact: Malicious PDFs can trigger invalid pointer use and crash the app.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Block untrusted PDFs at mail and web gateways.
- Mitigation: Patch promptly.
- CVE-2026-57242: PDF page object lifecycle crash
- Impact: Repeated invalid dereferences can crash the application.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Restrict active PDF content.
- Mitigation: Update the viewer and use sandboxing.
- CVE-2026-57244: PDF form reset re-entry crash
- Impact: Crafted resets can crash the application.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Disable interactive PDF features where possible.
- Mitigation: Apply the vendor fix.
- CVE-2026-57246: PDF signature plugin crash
- Impact: Abnormal objects can crash the application during signature handling.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Route suspicious PDFs away from signing workflows.
- Mitigation: Patch and validate input files.
- CVE-2026-57248: PDF annotation attribute crash
- Impact: Malicious annotation writes can crash the application.
- Affected Systems: PDF-handling application affected by the described flaw.
- Immediate Action: Block untrusted annotation-heavy PDFs.
- Mitigation: Upgrade the application.
- CVE-2026-53553: Goploy arbitrary file read via path traversal
- Impact: Authenticated users can read local and remote files, including secrets and SSH keys.
- Affected Systems: zhenorzz/goploy <=1.17.5.
- Immediate Action: Restrict access immediately and patch; assume exposed file contents may be stolen.
- Mitigation: Upgrade to a fixed release and verify all path inputs are namespace-checked.
- CVE-2026-9700: Eventer time-based SQL injection
- Impact: Unauthenticated attackers can extract sensitive database data.
- Affected Systems: Eventer up to 4.4.2.
- Immediate Action: Patch now and watch for unusual database latency.
- Mitigation: Update the plugin and review query logs for injection patterns.
- CVE-2026-9842: Backstage Customizer Demo Access privilege escalation
- Impact: Unauthenticated attackers can gain
manage_optionsand escalate to admin actions. - Affected Systems: Backstage - Customizer Demo Access up to 1.4.2.
- Immediate Action: Disable the demo access plugin and review WordPress roles.
- Mitigation: Patch and verify no unauthorized role changes occurred.
- Impact: Unauthenticated attackers can gain
What to Do Now
- Patch or disable every affected WordPress plugin, Goploy, Plesk, Coder, and Apriso deployment exposed to users.
- Prioritize internet-facing systems and any instance with low-privilege or tenant-based access.
- Rotate credentials for FTP, admin, SSH, and service accounts if any vulnerable system was reachable before patching.
- Review logs for unexpected plugin installs, file uploads, file deletions, remote URL changes, and repeated PDF crashes.
- Assume possible compromise on any unpatched Goploy or Plesk system with multi-tenant use.
Verification steps: confirm exact versions, check whether the vulnerable plugin or service is active, and validate that public endpoints are no longer reachable without strong authentication. For WordPress, audit installed plugins and recent admin changes; for Goploy, verify namespace-scoped authorization on project and file endpoints.
Monitoring recommendations: alert on new admin users, plugin activation events, file changes in web roots, suspicious outbound connections after deployment, and unusual PDF-related application crashes. Watch for signs of credential exposure and follow up with forced resets where needed.
Related Resources
- Internal analysis: Goploy multi-tenant authorization failures and WordPress plugin emergency response checklist (to be published).
- Official vendor advisories: WebPros Plesk, WordPress plugin maintainers, Coder security advisories, and vendor notices for DELMIA Apriso and PDF application updates.