cisaregulatorNewsThe Broadside1 min read

CISA Publishes Weekly Vulnerability Bulletin SB26-208

The bulletin includes a CVSS 9 fastjson RCE exploitable under the library's default configuration, plus three Apache MINA SSHD highs all patched in version 2.19.0.


TL;DR

CISA released its weekly vulnerability bulletin SB26-208 on July 27. The highest-scored entry is a CVSS 9 fastjson RCE (CVE-2026-16723) affecting versions 1.2.68 through 1.2.83, exploitable under default configuration. Other highs include an Adobe DNG SDK buffer overflow (CVSS 7.8), three Apache MINA SSHD issues patched in version 2.19.0, and AgenticMail API weaknesses (CVSS 8.2). The bulletin doesn't address active exploitation.

The CISA Vulnerability Bulletin SB26-208, released July 27, summarizes new CVEs recorded during the week of July 20. As with all weekly bulletins, entries are organized by CVSS severity and patch information is included when available. Some entries are compiled from external open-source reports rather than direct CISA analysis.

The highest-scored vulnerability in the bulletin is CVE-2026-16723, a remote code execution flaw in Alibaba's fastjson library affecting versions 1.2.68 through 1.2.83. It carries a CVSS score of 9 and is exploitable under fastjson's stock default configuration. The bulletin notes that no AutoType enablement or classpath gadget is required.

Apache MINA SSHD accounts for three separate high-severity entries: a path traversal in the sshd-scp component (CVE-2026-56452, CVSS 7.5), a Windows-specific path traversal in sshd-git (CVE-2026-56623, CVSS 7.1), and improper OpenSSH user certificate validation during authentication (CVE-2026-56624, CVSS 7.3). All three are fixed in version 2.19.0.

Additional highs include a stack-based buffer overflow in Adobe DNG SDK versions 1.7.1 and earlier (CVE-2026-48389, CVSS 7.8), which requires user interaction via a malicious file, and multiple weaknesses in AgenticMail API and core packages, patched in versions 0.9.32 and 0.9.10 respectively (CVE-2026-47255, CVSS 8.2). The ARforms plugin for WordPress is affected by stored XSS (CVE-2026-12421, CVSS 7.2). Other entries include unauthenticated XSS in AffiliateWP (CVE-2026-57809, CVSS 7.1) and CSRF vulnerabilities in Avada Core (CVE-2026-65471, CVSS 9.6) and ApusListing (CVE-2026-57785, CVSS 8.8). An authentication bypass in Appriss Insights VINE (CVE-2026-63359, CVSS 9.8) is also listed.

The bulletin doesn't indicate whether any listed vulnerability is under active exploitation.


Published ·Deep Fathom

CISA Publishes Weekly Vulnerability Bulletin SB26-208 — The Broadside