UpdateStar Vulnerability Index · July 2026
Monthly severity snapshot for widely-installed consumer software
74
Overall Score
SEVERE
July 2026 delivered the largest Patch Tuesday in Microsoft's history — 569 CVEs, more than 2.5× June's already-record 208. Two of those flaws (SharePoint, AD FS) were exploited as zero-days and landed on CISA KEV within days. Separately, Mozilla shipped an emergency Firefox release after confirming public exploit code for two critical flaws, and the WinRAR path-traversal bug from July 2025 is still being actively exploited by nation-state groups a full year later.
2 × KEV
Listed
Ongoing
Nation-State Exploitation
2 × Public PoC
569 MS CVEs
Top 5 — Consumer App Severity
#1
WinRAR
CVE-2025-8088
Path traversal → Startup folder · Nation-state
exploitation still widespread a year later (RomCom, Gamaredon, Paper Werewolf) · No
auto-update, ~500M users exposed
CISA
KEV
APT
Active
Patched
7.13
8.4
CVSS HIGH
#2
Adobe Acrobat Reader
CVE-2026-48373
Heap-based buffer overflow → arbitrary code execution ·
Requires opening a malicious file · Patched same day as disclosure
Patched
26.001.21662 (APSB26-63)
7.8
CVSS HIGH
#3
Mozilla Firefox
CVE-2026-15718 / -15719
Invalid-pointer JS/WebAssembly bug + Fission
site-isolation bypass · Mozilla confirmed public exploit code for both, no ITW attacks
observed yet · Auto-update reliable but needs a restart
Public PoC (both CVEs)
Patched Firefox
152.0.6
Critical
CVSS PENDING (NVD)
#4
Google Chrome
CVE-2026-15764 / -15765
Two critical use-after-free flaws in the Ozone display
layer · Sits at the OS trust boundary, closer path to sandbox escape · No confirmed
exploitation at disclosure, gradual rollout leaves an exposure window
Patched
150.0.7871.124/.125
Critical
CVSS PENDING (NVD)
#5
7-Zip
CVE-2026-14266
Heap overflow in XZ archive decoder · No auto-update · ZDI
advisory made details public Jul 15, ~3 weeks after the silent fix
Patched 26.02
7.0
CVSS HIGH
CVSS Score Comparison
WinRAR
8.4
Adobe Acrobat Reader
7.8
Firefox
Critical (pending)
Chrome
Critical (pending)
7-Zip
7.0
MS CVE-2026-57092
9.9
Key Stats — July 2026
569
Microsoft CVEs patched in a single Patch Tuesday (record)
2
MS zero-days exploited ITW & added to CISA KEV (AD FS,
SharePoint)
2
Firefox CVEs with confirmed public exploit code
365+
Days WinRAR CVE-2025-8088 under continuous nation-state
exploitation
−7
Days mean time-to-exploit (Mandiant M-Trends 2026)
43
Days median KEV remediation time (Verizon DBIR 2026)
Patch Lag — Days Since Disclosure vs. Update Status
WinRAR (CVE-2025-8088)
365+ d
Patched Jul 2025 · still under active nation-state
exploitation a year later, no auto-update
Adobe Acrobat Reader (CVE-2026-48373)
~7 d
Fixed Jul 17 · newly disclosed, no confirmed exploitation yet
Firefox (CVE-2026-15718 / -15719)
<10 d
Fixed Jul 14 · exploit code public, auto-update reliable but
requires restart
7-Zip (CVE-2026-14266)
~30 d
Silently fixed Jun 25 · ZDI advisory public Jul 15 · no
auto-update, no confirmed PoC/ITW
Data sources: NVD · CISA KEV · Mandiant M-Trends 2026 · Verizon DBIR 2026 · vendor
advisories (Mozilla, Google, Adobe, RARLAB, 7-Zip/ZDI, Microsoft MSRC)
Check and update all software at updatestar.com · Download the UpdateStar Client for Windows
Check and update all software at updatestar.com · Download the UpdateStar Client for Windows
July 2026 Highlights
- KEV3 CVEs on CISA Known Exploited Vulnerabilities list (2 new — AD FS & SharePoint, 1 carryover — WinRAR)
- APTWinRAR still under active nation-state exploitation a year after patch
- PoC2 CVEs (Firefox) with public proof-of-concept / exploit code
- MS569 Microsoft CVEs in a single Patch Tuesday — a new record
Overall Severity Score
Index Score
74 / 100
Rating
SEVERE
App Quick Reference
-
CRIT WinRAR
8.4 -
HIGH Acrobat Reader
7.8 -
HIGH Firefox
Critical* -
HIGH Chrome
Critical* -
MED 7-Zip
7.0
Patch Status
- WinRAR — patched but no auto-update, still actively exploited
- Acrobat Reader — patched (Jul 17)
- Firefox — patched (auto-update, restart required); exploit code circulating
- Chrome — patched (staged/gradual rollout)
- 7-Zip — patched but no auto-update
Data Sources
- NVD (National Vulnerability Database)
- CISA Known Exploited Vulnerabilities
- Mandiant M-Trends 2026
- Verizon DBIR 2026
- Vendor security advisories